This is up as the room comes in and sits down. Do not advance past it until you actually start. It earns a laugh from about half the room and quietly tells the other half that the next forty minutes are not a vendor keynote.
"Right — and now for something completely different."
Then advance straight to the title. Do not explain the joke, and do not add a second one. The whole value of this slide is that it costs three seconds and changes the temperature of the room before you have said anything substantive.
If the audience skews younger than the reference, it still works — a man at an office desk on a beach is funny without the footnote, and it is a decent visual for a talk about infrastructure in the wrong place.
ADA AI Leadership Day 2026
Beyond the Clouds
Sovereign AI infrastructure, and what it actually takes to regain control.
Timing target: 22 min of content, 23 min of debate. This room is 80 founders/directors, not a KubeCon audience. Do not open with architecture.
"I build AI infrastructure for a living. Today I want to argue that the most important AI decision you'll make this year isn't which model — it's whose jurisdiction you run it in."
Set the contract early: "I'll talk for twenty minutes, then I want to argue with you for twenty-five. There's a slide at the end with five things I think are true and you might not."
Before we start
How this session works
- 01Twenty to twenty-five minutes of meThat is all the talking I plan to do. The rest of the time belongs to the room.
- 02Interrupt meIf a number looks wrong or a word doesn't land, say so in the moment. Quick questions are welcome mid-flow — you are not being rude.
- 03Save the big onesThe real arguments are worth more with everyone in them. There is a slide at the end built for exactly that.
The last slide has five things I believe and you might not. That is where we spend the second half.
Thirty seconds, and mean it. This slide is the contract for the session. Setting it explicitly is what gives you permission to be provocative later — and what gives them permission to push back rather than sit politely.
"Two things before I start. First, interrupt me — if a number looks wrong or something doesn't land, say so there and then, you're not being rude. Second, if it's a big one, hold it. There's a slide at the end with five things I believe and you might not, and that's where I want to spend the second half."
Rule 2 is the one that changes the room. A leadership audience will stay silent for twenty-five minutes out of politeness unless you explicitly licence them not to. Say it and then honour it — take the first interruption warmly, however small, because the rest of the room is watching what happens to the person who goes first.
If the organisers have given a hard stop, say the actual end time out loud here. It is the only housekeeping the room genuinely wants.
The best time to plant a tree was twenty years ago. The second best time is now.Chinese proverb
Fifteen seconds. Say it once, do not explain it, and go straight into the question on the next slide. The proverb is doing one job: giving the room permission to have got this wrong so far.
"I want to put one thing up before I start, because everything I'm about to show you is going to sound like bad news. Nobody in this room is behind. The decisions that created this were reasonable when they were made. The only question worth asking is what you do from today."
This matters for a leadership audience specifically. The next forty minutes are an argument that their current architecture carries a risk they did not price — and a defensive room argues with the evidence rather than with the conclusion. Take the blame off the table first and they will engage with the substance.
Cut if you are running late before you even start. It is the most expendable slide in the deck — but it is also the cheapest way to keep the room open.
Could you move your AI workloads to another provider in ninety days?
Show of hands — then keep them up if you've tested it
Do the show of hands. Wait for it. Roughly a third go up on the first question; almost none stay up on the second. That gap is the talk.
"Right. So most of us believe we could. Almost none of us have proved it. In every other part of the business we'd call that an untested disaster recovery plan."
"Just use the API" was never an architecture decision. It was a procurement decision that quietly outsourced your jurisdiction.
The thesis of this talkLand this slowly. The word that does the work is jurisdiction — not "data", not "privacy". Leaders in this room already own jurisdiction risk in every other supplier contract.
"Nobody signed off on a foreign-policy exposure. Somebody signed off on a credit card and a rate limit. Those turned out to be the same decision."
The ground moved
Four things changed between your last AI budget cycle and this one. None of them were announced by your vendor.
Section is ~5 min. Purpose: establish that this is not a philosophical debate about sovereignty, it's a live risk register update. Facts only, no advocacy yet.
Start with where you actually are
European cloud providers' share of their own home market, against everyone else's. The market grew sixfold. Their share of it halved.
The plateau is the uncomfortable part. Three years of sovereignty debate, a €74bn market growing 24% a year, and the European share has not moved off 15%. Rhetoric did not shift a single point of it.
Synergy Research Group, July 2025 · European cloud infrastructure services, share of the European market
Forty-five seconds. This is the baseline the whole talk sits on, and it is the slide that makes the room uncomfortable in the right way. Do not editorialise — the two numbers do it.
"Before anything else, here is where we are. In 2017 European providers had twenty-nine percent of their own market. Today it's fifteen, and it has been fifteen for three years. The market grew sixfold in that time — the share halved."
The plateau matters more than the decline. Anyone can dismiss a decline as the past. A plateau through the loudest three years of sovereignty rhetoric in European history says the talking is not working, which sets up the "procurement, not manifestos" line later.
If challenged on the definition: this is Synergy's cloud infrastructure services measure, European providers' share of the European market. The complement is not all US — but it is overwhelmingly US, and the next slide shows it.
Three companies, seventy percent
Amazon, Microsoft and Google together hold roughly 70% of the European cloud market. The largest European provider holds two.
Synergy Research Group, 2025 · European cloud infrastructure services
There is no European hyperscaler waiting to take the workload. That is the real problem with "just move to a European provider" — and it is exactly why the rest of this talk is about owning a control plane rather than running a migration.
Twenty seconds, and only one line. The previous slide gave them the trend; this one gives them the concentration. Point at the 2%.
"Seventy percent of the European cloud market is three American companies. The largest European provider is two percent. When people say 'just move to a European alternative', that is the alternative they are talking about."
This is the slide that makes the jurisdiction argument concrete rather than theoretical. It also pre-empts the naive version of the answer — there is no European hyperscaler waiting to take the workload, which is exactly why the talk is about control planes and per-workload decisions rather than a single migration.
Cut this one before the previous one if you need to lose a slide. The trend carries more weight than the split.
We cannot guarantee that French citizens' data will not be handed to US authorities without their consent."Anton Carniaux, Director of Public & Legal Affairs, Microsoft France — under oath, French Senate inquiry into digital sovereignty, 21 July 2025. Microsoft's technical director added that a contractual guarantee keeps EU customer data in the EU. A contract is not a jurisdiction.
The single most useful slide in the deck for this audience. It is not an activist claim — it's sworn testimony from the vendor most of this room already buys from.
Be scrupulously fair: he also said it had never actually happened, and Microsoft has since strengthened its EU Data Boundary. The point is not that Microsoft is untrustworthy. The point is structural: no US-parented company can contract its way out of the CLOUD Act.
"This is the vendor's own lawyer, under oath. Nobody is accusing anyone of anything. He's describing the structure of the problem more honestly than most of us do in our own risk registers."
Four dates that changed the calculus
- 21 JUL 2025Microsoft France testifies
Cannot guarantee EU data is beyond US reach. Contractual, not jurisdictional.
- 15 JAN 2026AWS European Sovereign Cloud goes live
€7.8bn, Brandenburg, EU-incorporated parent, EU-resident operators. The hyperscalers concede the premise.
- 29 JUN 2026Trump v. Slaughter
US Supreme Court removes for-cause protection for FTC commissioners — the independence the adequacy decision relied on.
- 31 JUL 2026EDPB writes to the Commission
Asks it to assess whether the FTC can still uphold Data Privacy Framework commitments. A review, not a revocation — yet.
Walk it left to right in about 90 seconds. The arc: the vendor admitted it → the vendors responded to it → the legal ground under the response moved anyway.
On AWS: this is genuinely a serious offer, and note what it concedes. €7.8bn is not a marketing budget. If sovereignty were a fringe European anxiety, they would not have built a separate legal entity for it.
On Slaughter/EDPB: the General Court upheld the Data Privacy Framework in September 2025 (the Latombe case). Transfers are lawful today. But the adequacy decision explicitly leaned on FTC independence, and that premise is now contested. Schrems III is a question of when, not whether.
"Three times in ten years, the legal basis for transatlantic data transfer has been struck down. If your AI architecture assumes it survives a fourth challenge, that's a bet, not a plan."
And the AI Act deadline you were braced for — moved
The Digital AI Omnibus, agreed May 2026, deferred the high-risk regime. Read what it did not defer.
- Deferred → Dec 2027Annex III high-risk obligations, originally 2 Aug 2026. Annex I embedded systems slip to Aug 2028.
- In force nowArticle 5 prohibitions. GPAI model obligations (Art. 51–56) — untouched by the omnibus.
- In force nowArticle 50 transparency for AI-generated content; grace for existing systems ends 2 Dec 2026.
- UnchangedPenalties up to €35m or 7% of global turnover. The AI Office gained inspection powers.
Anticipate the room's reaction: half of them read "delay" in the press and quietly deprioritised the programme. Correct that gently.
"Deferred is not cancelled. And the deferral bought you eighteen months on the paperwork — it bought you nothing on the architecture, because the architecture takes longer than the paperwork."
Key leadership framing: the omnibus moved a compliance deadline. It did not move a capability deadline. You cannot procure explainability, audit trails, and model lineage in the last quarter before an inspection.
The rulebook is already written — and it doesn't move at headline speed
Six European laws now touch how you run AI. One of them is quietly about to make leaving your cloud provider free.
Nothing on this chart is a proposal. Every bar is law that has already been adopted.
Ninety seconds. Do not read the chart. Point at three things: the red line is today, everything left of it already binds you, and the single black pin on the Data Act row is the one that changes your negotiating position.
"Every conversation I have about sovereignty starts with someone saying 'let's wait and see what Brussels does'. Brussels already did it. This is the past, not the future."
The Data Act pin is the slide's payload. From 12 January 2027 a cloud provider may not charge you to leave — no switching fee, no egress fee. The thing that has locked most organisations in for a decade is being legislated to zero, in sixteen months. If your exit was uneconomic, it is about to stop being uneconomic. That is a procurement lever, and it expires as a novelty the moment everyone notices.
If asked about the AI Act pins: prohibitions since Feb 2025, GPAI obligations since Aug 2025, transparency grace ends 2 Dec 2026, high-risk deferred to Dec 2027 by the omnibus. Say it once, don't dwell.
Six laws, one question underneath all of them
Strip out the acronyms and every one of these asks the same thing: can you demonstrate control, and can you leave?
| Law | What it actually asks of you | Where you already are |
|---|---|---|
| GDPRReg. 2016/679 | Know where personal data physically goes and under whose courts it sits. | Binding since 2018. Chapter V transfers is the part that has now been litigated three times. |
| NIS2Dir. 2022/2555 | Own the security of your suppliers, with named personal accountability at management level. | National law since October 2024. |
| DORAReg. 2022/2554 | If you are a financial entity: register your critical ICT providers and prove you could exit each one. | Applies since 17 January 2025. Regulators are already asking. |
| Data ActReg. 2023/2854 | Your provider must let you leave — and from 12 Jan 2027 may not charge you a cent to do it. | Applicable since 12 September 2025. The clock on free exit runs out of excuses in 16 months. |
| AI ActReg. 2024/1689 | Classify every AI system you run, and produce evidence on demand: lineage, evaluations, human oversight. | Prohibitions and GPAI duties in force. High-risk deferred to December 2027 — the paperwork, not the architecture. |
| Cyber Resilience ActReg. 2024/2847 | Anything you ship with digital elements needs a security lifecycle and a bill of materials. | Incident reporting from September 2026; full application December 2027. |
This is the slide the room photographs. Deliver the second column only — the third column is for the people who read the photo afterwards.
"Six laws, six acronyms, one question. Can you show who controls this, and can you walk away. If you can answer those two for every AI workload, you are compliant with all six by construction."
Cut this slide first if you are short on time — the gantt carries the argument on its own.
The DORA row is the one that lands with anyone from financial services, and there are usually six or seven of them in a room this size. Exit testing is already an examined requirement for them; the rest of the room is roughly three years behind.
of organisations now factor an AI vendor's country of origin into selection decisions
Deloitte, State of AI in the Enterprise 2026 · n=3,235 · 24 countries
This slide exists to tell the room they are not outliers. Nearly 60% in the same study say they build primarily with local vendors.
Two supporting numbers, say them, don't slide them: Broadcom's 2026 private cloud study has public cloud as the primary inference environment falling from 56% to 41% in a single year. Cloudian has 93% of enterprises repatriating, in-process, or evaluating.
"Whatever you think about sovereignty as a principle, it has already become a procurement criterion. Your customers are about to start asking you this question, if they haven't."
This is no longer a minority position
Five numbers from five separate 2026 surveys. None of them were commissioned by anyone selling sovereignty.
The last bar is the only one moving downwards. It is also the only one about where the money goes.
Do not read all five. Read the top one and the bottom one, and let the shape do the rest.
"Ninety-three percent. Whatever you think of sovereignty as a principle, the market has already voted, and it voted with procurement forms rather than manifestos."
The bottom bar is the important one because it is a delta, not a level. Fifteen points of primary inference workload left public cloud in a single year. That is not ideology, that is a bill someone read.
If challenged on survey quality — fair challenge, take it seriously: these are vendor-adjacent surveys with self-selected samples. Answer honestly: "Every one of these has a house bias. That's exactly why I'm showing you five from five different houses that all point the same direction."
Sovereignty is a dial, not a switch
The unproductive version of this debate is "cloud or on-prem". The productive version is "which level, for which workload, at what price".
Section ~5 min. This is the reframe that makes the rest of the talk actionable, and it's the part most likely to change what someone does on Monday.
The dial already has numbers on it
You do not have to invent a sovereignty scale. The Commission published one, and it is procuring against it.
- It is a real document, not a consultation or a position paper.
- It computes a score — eight dimensions, weighted, comparable between suppliers.
- It has already moved money: €180m awarded in April 2026.
- You can put it in a tender on Monday, with no new policy work.
European Commission
Directorate-General for Digital Services
Luxembourg
Cloud Sovereignty Framework
Version 1.2.1 — October 2025
- Introduction
- Sovereignty Objectives
- Sovereignty Effective Assurance Levels
- Assessment of Sovereignty Effectiveness
- Computation of Sovereignty Score
Twenty seconds. Hold up the document, then go straight to the next slide for what the levels mean. Do not read the contents list aloud — it is there so the room can see this is an operational document with a scoring method, not a manifesto.
"This exists. Version 1.2.1, October last year, from the Commission's own digital directorate. Section three defines the levels, section five tells you how to compute a score. Somebody has already done the hard part of this argument for you."
The two highlighted lines are the ones that matter: assurance levels and computation of a score. A level plus a formula is what turns sovereignty from a values conversation into a procurement requirement — which is the whole point of this section.
Safe to cut if you are behind: the SEAL table on the next slide carries the argument alone. This slide's only job is to prove the framework is real to anyone who assumes it is aspirational.
The scale itself: SEAL 0 to 4
Sovereignty Effective Assurance Levels. Five rungs, scored across eight dimensions — legal, operational, supply chain, technological openness, security, environmental — and totalled into one comparable sovereignty score. They do not say a provider is good or bad. They say how much of your control is contractual and how much is structural.
April 2026 · €180m awarded to Post Telecom, STACKIT, Scaleway and Proximus — most at SEAL-3, Proximus at SEAL-2. No hyperscaler bid at SEAL-3.
Ninety seconds, one rung per click. Do not read all five — read 0, 2 and 3, and let them see the bars grow. The whole slide exists so that "how sovereign are you?" becomes a number a supplier has to write down.
"Stop arguing about whether you're sovereign. There's a five-point scale, the Commission scores suppliers against it across eight dimensions, and it just spent a hundred and eighty million euros using it. Pick a number per workload, write it into the requirement, and make suppliers answer it. That's a procurement problem, and you already know how to run those."
The gap between 2 and 3 is the whole talk. SEAL-2 is what a contract can buy you — it fails the moment a foreign court instructs the parent company. SEAL-3 is what an architecture buys you. That is the same distinction as the Microsoft testimony on slide 10, expressed as a procurement level.
If someone challenges SEAL-4 as unachievable: agree immediately, without hedging. Nothing operates there at scale, and that is precisely why the EU is funding gigafactories. Conceding it costs you nothing and buys you the rest of the argument.
Worth saying out loud: no hyperscaler bid at SEAL-3. They bid, and they landed lower. That is not an accusation, it is the structure of the thing.
Four questions, asked per workload — not per company
- JurisdictionWhich court can compel this data, and who is legally capable of refusing? Not "where is the region".
- PortabilityIf the price triples or the model is deprecated on Friday, what is the actual cost of leaving? Measure it in weeks.
- EconomicsAt your real utilisation, not your peak slide — where does the crossover sit?
- CapabilityIf this becomes core to the business, do you want to be able to build it, or only to buy it?
The load-bearing word is per workload. Your marketing copy generator and your claims-adjudication model do not deserve the same answer, and a company-wide "AI policy" that gives them the same answer is how you end up over-paying and under-protected simultaneously.
"Most organisations have one AI policy and forty AI workloads. That's the mistake. Sovereignty is a per-workload property, like data classification — and you already classify data."
What actually changes when you own the control plane
- Capability arrives in days
- Cost scales with success, forever
- Model deprecated on the vendor's schedule
- Audit trail is whatever the vendor exports
- Terms of service change without your consent
- Zero infrastructure headcount
- Capability arrives in weeks, once
- Cost is a fixed floor plus marginal compute
- You choose when a model retires
- Every prompt, retrieval and response is yours to log
- Terms change when you change them
- Real platform engineering, hired and retained
Do not let the right column look free. Read the last line of each column aloud, deliberately. That is the honest trade and the room will trust everything after it more.
"The right-hand column is not better. It's different, and it's yours. Anyone who tells you the right column has no cost is selling you the right column."
You are not the first person in Europe to say this out loud
This must be Europe's independence moment.
Ursula von der Leyen · State of the Union address, European Parliament, 10 September 2025We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure.
Ursula von der Leyen · same addressUnite and act — or face a slow agony.
Mario Draghi · The Future of European Competitiveness, 9 September 2024. He called it an existential challenge.Build the factories, so we become AI makers, not AI takers.
Han de Groot · on why the Netherlands is building its own AI capacityThirty seconds, and read only two of them aloud. Pick von der Leyen's second quote and Draghi's. The wall is there so the room can read the rest while you talk.
"I'm an infrastructure engineer, so it's slightly uncomfortable to find myself agreeing with a Commission President. But the reason this is on the slide is that it's now the official position of the single market you sell into. Sovereignty stopped being an opinion and became a policy environment."
The point to make, and it is the load-bearing one for a leadership audience: political will has already turned into procurement rules and money. €180m awarded, €20bn+ expected in gigafactories, InvestAI mobilising €200bn. Whether or not the rhetoric moves you, the budget lines are real and your competitors are bidding into them.
If someone rolls their eyes at Brussels rhetoric — good, that is provocation #1 on the debate slide. Say so, and bank it for the Q&A rather than fighting it here.
Three answers to "who decides the roadmap?"
Sovereignty is not only about where the servers sit. It is about who governs the thing you depend on — and the world has three working answers to that, not one.
US model
Platform control
GitHub · PyPI · npm
- The forge, the registry and the package index are US-hosted chokepoints
- Sanctions become instant service denial, with no recourse and no notice
- Open code, closed platform. Ownership of the commons by ownership of the plumbing
China model
Domestic forks
Gitee · OpenAtom · OpenHarmony
- A national mirror of the whole stack, built as a response to sanctions
- It works — and it costs you interoperability and shared visibility
- Two ecosystems that no longer read each other's code
European path
Interdependent autonomy
Sovereign Cloud Stack · GAIA-X · Digital Commons EDIC
- Not isolation — strategic participation, and influence over the roadmap
- Sit on the boards, fund the maintainers, hold the standards
- Open governance beats ownership, and it is far cheaper
The third column is the awkward one — and it is the right one. Forking Europe out of the global commons would cost as much as staying captured by it. The lever is governance, not ownership.
Sixty seconds. This slide answers the objection you will otherwise get in the debate — "isn't sovereignty just protectionism?" Show them there is a third column, and that it is the one Europe is actually funding.
"There are three ways to answer 'who decides the roadmap'. America owns the platform. China built its own copy. Europe's bet is that you can stay in the commons and still have a vote — which is the only one of the three that doesn't require you to be a superpower."
The middle card is not a cheap shot at China. It is genuinely effective and genuinely costly, and saying so plainly is what earns you the right to argue for the third column.
Links to provocation #1 on the debate slide. If someone wants the protectionism fight, this is the slide to come back to.
The stack is ready — that's the news
Three years ago this argument failed on engineering grounds. It doesn't any more, and that's the part the room probably hasn't been told.
Section ~5 min. Energy shift: sections 1–2 were risk, this is opportunity. Change your voice here.
AI infrastructure became boring. Boring is the achievement.
- 66%of organisations serving generative AI models already run inference on Kubernetes. This is the mainstream, not the fringe.
- 31 certified platformsunder the CNCF Kubernetes AI Conformance programme as of March 2026 — up from 18 in November 2025.
- Portability is now testableConformance covers disaggregated inference, inference ingress, GPU-aware scheduling. Portable means certified portable.
- The hard parts got donatedllm-d — Red Hat, Google, IBM, NVIDIA, CoreWeave — entered the CNCF in March 2026. Prefill/decode disaggregation and KV-cache-aware routing, open.
Translate every term. "Disaggregated inference" = the expensive trick that makes GPUs 2–3× more efficient, which used to be proprietary and now isn't.
"The reason I can stand here and make this argument in 2026, when I couldn't in 2023, is that the difficult engineering has been commoditised — by the people selling the alternative. That is unusual, and it's the window."
If challenged on maturity: llm-d benchmarks around 120k tokens/sec on 16 H100s with Qwen3-32B. Real numbers, open code, reproducible.
"Open weights" is not the same thing as an open model
The substrate is solved. The model layer is not — and the word "open" is doing a great deal of work in vendor marketing right now. There are three tiers, and only one of them survives the sovereignty test.
Tier 1
Closed APIs
GPT-5 · Claude · Gemini
- No inspection, no control, no say in when it is retired
- The vendor holds the pricing power and the terms of service
- Genuinely the best capability available — that is why it is tempting
Tier 2
Open weights
Llama 4 · DeepSeek R1
- You can read and run the weights — a real improvement
- But: licence restrictions, no training-data audit, geopolitical entanglements
- Portable, not accountable. Enough for lock-in, not enough for an AI Act file
Tier 3
Actually open
OpenEuroLLM · Mistral + EU infrastructure
- Inspectable, forkable, and deployable on infrastructure you control
- The only tier where you can answer an auditor without phoning a vendor
- Behind the frontier today — and closing, which is the whole bet
The question to ask any supplier: is a model "open" if you can read the weights but cannot audit the training data, verify the alignment, or run it without GPU capacity you do not control?
This is the honesty beat inside the good-news section. The previous slide said the stack is ready; this one says the model layer is the part that genuinely is not, and you would rather they heard that from you than from a vendor.
"Everybody in this room has been told they can have an open model. Read the middle card. You can download the weights, you cannot audit what went into them, and the licence still tells you what you may build. That's portable — it isn't accountable."
Ties directly to the workload table later: rent the frontier knowingly, through your own gateway. This slide is why "knowingly" is in that sentence.
If challenged that tier 3 is behind: agree, immediately and without hedging. Then note that tier 3 is the only one you can put in front of a regulator without a vendor on the call.
Don't take my word for it — take theirs
In March, KubeCon Europe brought the cloud-native industry to the RAI, twenty minutes from this room. This is a sample of what it spent the week on. Note who is presenting: not activists, not startups.
- Building a Sovereign, Multi-Cloud Strategy with Cloud Native Technologies Goetz Reinhaeckel, Program Director Cloud — BWI, the IT company of the German armed forces. Main-stage keynote
- Inference and Sovereign AI: Scaling Cloud Native AI with Control and Compliance Karena Angell, Technical Strategist; Vincent Caldeira, CTO APAC — Red Hat. Sponsored keynote
- Towards Building an Open Source AI Reference Stack for EU Sovereign Cloud Madhav Bhargava, SAP Labs; Sanjay Chatterjee, NVIDIA. Europe's largest software company and the company selling the chips — building the open alternative together
- Virtualizing Large-Scale GPU Cluster for Sovereign AI Jian Li — SK Telecom, on the Petasus AI Cloud. A national telco doing exactly this, at scale, outside Europe
- Sovereign Identities for Your Cloud Native Architecture Alexander Schwartz, IBM; Sebastian Laskawiec, Defense Unicorns. Who your systems believe you are is also a sovereignty question
- EU Cloud Sovereignty Framework Explained Emiel Brok, SUSE — the SEAL levels, in practice. Co-located event · the framework from slide 10, unpacked
- Running a Sovereign Cloud Stack Cluster for the ITU: Lessons Learned Martin Pilka, dNation; Karsten Samaschke, VanillaCore. The UN's telecoms agency, in production, with the lessons written down
Fifteen seconds of delivery, then move. This slide is not read aloud — it is shown. Its entire job is to convert "this is one consultant's opinion" into "this is where the industry already is".
"KubeCon Europe was at the RAI in March — twenty thousand engineers, twenty minutes from here. These are seven sessions from that week. SAP. NVIDIA. IBM. Red Hat. The German armed forces. The United Nations' telecoms agency. Nobody on this slide is a European sovereignty activist. They are all just shipping."
The two to name if you name any: BWI, because a defence IT provider building on cloud-native rather than a closed national stack is the strongest possible signal that this is achievable; and SAP with NVIDIA, because the vendor everyone assumes has the most to lose from an open sovereign stack is co-authoring one.
Every title is a live link in the shared deck. Offer that — several people will want to send one to a colleague.
The reference architecture
OCI images
OpenAI-compatible API
S3 API
Open weights
Every boundary is a standard, so every layer is an exit.
Model registry
Eval harness
Prompt & response lineage
Immutable audit log
The AI Act evidence layer. Build it first, not last.
Every layer open, every layer replaceable. No layer requires a US-parented supplier.
90 seconds maximum. This slide is proof of depth, not the argument. Do not read the chips — point at three things and move.
The three things: (1) the gateway layer is where you enforce policy, redaction and routing — it's the single highest-leverage thing to own; (2) the data layer is the moat, and it's the layer nobody should ever have rented; (3) the bottom layer is the one you cannot download, which is why the next slides are about Europe's build-out.
"There is nothing exotic on this slide. That's the point. Every one of these is boring, documented, and someone else's problem to maintain."
If a technical person asks what I'd actually run: Talos, Cluster API, Argo CD, Kueue with DRA, KServe fronting vLLM, Milvus, OTel to a ClickHouse-backed store. Happy to go deeper in the bar.
And Europe is building the bottom layer right now
- 19 AI Factories, 13 antennasOperational across the EU today, EuroHPC-funded, accessible to industry and SMEs.
- Up to 7 AI Gigafactories>€20bn expected private investment. Bids close 12 November 2026, selection early 2027, operating within 18 months.
- €180m already committedCommission cloud procurement awarded to four European providers against the sovereignty framework, April 2026.
- The point for youSovereign capacity is becoming procurable. In 2023 the honest answer was "there's nowhere to go". That excuse is expiring.
Keep this factual and brief — this room does not need EU policy advocacy, they need to know the option exists.
"You don't have to have an opinion about industrial policy to notice that the supply side is arriving. The question stops being 'is there an alternative' and starts being 'have you evaluated one'."
The bottom layer, in megawatts
Announced and under construction in Europe. The unit that matters is not GPUs — it is grid connection, because that is the thing you cannot order faster.
€180m committed by the Commission · €7.8bn AWS European Sovereign Cloud · >€20bn expected across up to 7 EU AI Gigafactories
The visual argument is the gap between the bottom two bars and the top one. Do not explain it — let them see it, then say the line below.
"The bar at the bottom is live this month, twenty kilometres from this room. The bar at the top is the same company in 2027. That is a fifty-seven-fold step change in about eighteen months, and the constraint on it is not chips or capital. It is a grid connection."
Disclose again if you have not already: Lovelace Engineering consults for VOLT. Nebius is on the chart precisely so this is not a single-vendor slide.
The number to have ready if anyone asks what 800 MW means: roughly the draw of a small city, and roughly a fifth of the total contracted datacentre load in the Netherlands today. Grid congestion is why this is hard, and why the queue matters more than the cheque.
Cut this slide if you are short — the 800 MW metric slide that follows makes the same point in five seconds.
What it looks like when someone actually builds it here
VOLT — "from power to tokens" — is doing the full-stack version in the Netherlands. Worth knowing because it's twenty kilometres from this room, not because it's the only one.
- Dutch AI Cloud, operational October 2026Amsterdam, with NorthC Datacenters and Dell. 14 MW initially at Switch AMS4, 42 MW planned at AMS5.
- Rotterdam AI GigafactoryUp to 800 MW and roughly 250,000 GPUs, construction from 2027.
- Target sectorsFinance, healthcare, biotech, defence, government — precisely the workloads that cannot answer the jurisdiction question with a contract.
- The framing to stealHan de Groot: build AI factories so countries become "AI makers, not AI takers".
Disclose the relationship. Say plainly that Lovelace Engineering consults for Volt. Credibility in this room is worth more than the plug, and disclosing costs nothing.
"Full disclosure — I work with these people. Which is also why I know the numbers are real and how hard the grid connection was."
Nebius is the useful contrast if asked: 310 MW in Lappeenranta, 240 MW near Lille, targeting 2.5 GW. Different model — hyperscale neocloud rather than full-stack sovereign.
Rotterdam, from 2027. Sovereignty is, in the end, a question about electricity.
VOLT AI Gigafactory · ~250,000 GPUs · construction begins 2027
Short beat. Use it to make the point that the constraint everyone ignores is grid capacity, and in the Netherlands specifically, grid congestion is the binding constraint on AI ambition — not talent, not capital.
"Every AI strategy in this country eventually becomes an energy strategy. The organisations that figure that out eighteen months early get the connection."
What the vendor keynote leaves out
If I only told you the good half, you'd make a bad decision and I'd deserve the blame.
Section ~4 min. This is the credibility section. Do not rush it, and do not soften it — the honesty is what makes the recommendation land.
Four failure modes nobody demos on stage
- GPU scheduling contentionOne team's training job starves everyone's inference. Fixable — quotas, gang scheduling, fair-share — but it is a political problem before it is a technical one.
- Cold startsProvisioning a scarce GPU: seconds to hours. Pulling a large image: 3–5 minutes. Then weights load. "Scale to zero" is a slide, not a capability.
- Capacity planning without an escape hatchNo elastic overflow. You size for peak, or you queue. Both cost money and one costs credibility.
- Model lifecycle is now your jobEvals, regressions, retirement. The vendor was doing unglamorous work you never saw an invoice for.
Say the quiet part: the first failure is organisational. GPU contention is a governance problem wearing a Kubernetes costume, and it lands on someone in this room, not on the platform team.
"I've watched a data science team and a product team fight over eight GPUs for six weeks. No technology fixed it. A quota policy and one uncomfortable meeting fixed it."
Mitigation to name if pressed: keep a federated burst path to a European neocloud so you own the steady state and rent the spikes. That's the hybrid answer and it's the right one for most of this room.
Open source is the floor, not the ceiling
The maintenance crisis
- Log4j proved that unmaintained open source is a systemic risk, not a strategic asset
- Your production stack rests on components maintained by people nobody pays
- "We moved to open source" is a procurement event. Staying safe is an operating cost
- Open source without funded maintenance is a liability wearing the word sovereignty
Closing the gap
- Germany's Sovereign Tech Agency is proof that public funding for maintenance works
- Public procurement is the biggest untapped lever — the money already flows, into proprietary silos
- Fund, or staff, the three dependencies you genuinely cannot replace
- Cheaper than the licence you were paying, and it buys you a seat at the roadmap
"The innovation fetish is unhealthy. Maintain what is there." The cheapest sovereignty on this slide costs less than the licence it replaces.
The counterweight to section 03. You have just spent five minutes telling them the open stack is ready; this is the bill that comes with it, and saying it yourself is what makes the recommendation trustworthy.
"The innovation fetish is unhealthy. Maintain what is there. If you adopt an open stack and fund none of it, you haven't become sovereign — you've moved your dependency somewhere with no support contract."
The practical ask for this room, and it is small: identify the handful of dependencies you could not replace in a quarter, and put a name and a budget line against each. Most organisations cannot list them.
Pairs with the debate slide: ask how many of their production dependencies are maintained by a single unpaid contributor. Nobody knows, and the not-knowing is the point.
The economics: this is a utilisation question, not an ideology question
A single H100 delivers anywhere from $0.21 to $15.25 per million output tokens. Same hardware. The variable is you.
- Steady and high volume winsFixed floor plus cheap marginal tokens beats per-call pricing — above the crossover, and only above it.
- Bursty and low volume losesYou will pay for idle silicon and call it sovereignty. Don't.
- Do the cheap things firstCaching, batching, routing, right-sizing the model. Most "we need our own GPUs" cases evaporate here.
- Then measure, don't modelRun one real workload for one month. Utilisation is measured, never assumed.
Explicitly give the room permission not to self-host. That's what makes the rest credible — and it's true.
"If your AI spend is €4,000 a month and spiky, self-hosting is a hobby. Come back when it's €40,000 and flat. And notice that most of you will get there faster than you think — that's the part worth planning for."
Deloitte's TMT analysis puts on-prem at 50%+ savings over three years above the volume threshold. Note the caveat clearly: above the threshold.
One chart decides this, and it isn't a chart about sovereignty
The same H100 costs between $0.21 and $15.25 per million output tokens. Nothing about the hardware changes. The only variable is how busy you keep it.
Log scale. Curve is fixed cost divided by utilisation, anchored on the two published endpoints. Your crossover is wherever your own API line cuts it.
This is the most useful slide in the deck for a CFO, and the one to slow down on. Two minutes. It also gives the room permission not to self-host, which is what makes the rest of the talk credible.
"Same silicon. Seventy-fold difference in unit cost. Everything people argue about under the word sovereignty is, financially, an argument about where their own vertical line sits — and almost nobody in this room has measured it."
How to walk it: (1) the red dot is a GPU you bought and did not keep busy — that is the failure mode, and it is the expensive one; (2) the red dashed line is your current API bill, and everyone's sits somewhere different; (3) where it cuts the curve is your break-even utilisation; (4) left of that, renting is simply correct.
Be scrupulous about the caveat: the curve shape is arithmetic — fixed cost over utilisation — anchored on the two published endpoints. It is a shape, not a quote for your workload. Say that out loud if a numbers person is in the room; it costs you nothing and buys you everything.
The takeaway to state explicitly: you cannot get this from a slide, you get it from a month of measurement. That is move three in the ninety-day plan.
Self-host, federate, or rent — by workload class
This is the blueprint, compressed. You do not need one answer; you need this table filled in for your own portfolio.
| Workload | Verdict | Why |
|---|---|---|
| Data & retrieval layer | Self-host, always | It is your proprietary corpus. Renting it is the one decision with no upside. |
| Inference gateway & policy | Self-host, always | Control, redaction, routing and the audit trail all live here. This is the cheapest sovereignty you can buy. |
| Steady production inference | Self-host | Predictable volume, open weights, regulated data. Best economics and best jurisdiction answer. |
| Training & fine-tuning | Federate | Bursty and capital-intensive. Rent EU capacity — AI Factories, European neoclouds — keep the weights. |
| Frontier-model capability | Rent, knowingly | You will not match it. Route to it deliberately through your own gateway, with a documented exit. |
If you cut one slide for time, do not cut this one. This is the "blueprint" the abstract promised, and it's what people photograph.
The load-bearing insight is row two: you can rent the model and still own the control plane. Most of the sovereignty benefit at a fraction of the cost — and it is achievable in a quarter.
"You do not have to leave the hyperscalers to stop being captured by them. You have to own the layer where the decisions are made."
The capability is the point — and it is a people decision
- You are buying optionality, not serversThe asset is a team that can move a workload. The infrastructure is the by-product.
- Two to four people, not a departmentA capable platform team running a sovereign AI stack is smaller than the compliance function it de-risks.
- The skills are transferableKubernetes, GitOps, observability. You are not hiring exotica; you are hiring platform engineering.
- The risk is real and mundaneKey-person dependency. Mitigate with boring standard tooling — the same reason to avoid a bespoke stack.
This is the slide that connects to the day's third theme — People on board. Name it explicitly; the organisers will appreciate it and the room will feel the coherence.
"Every question in this talk that sounds like an infrastructure question is a hiring question in disguise. The organisations that will be sovereign in 2029 are the ones that hired two platform engineers in 2026."
Ninety days. Four moves. No new budget line.
- Weeks 1–2 · InventoryList every AI workload, its jurisdiction, and its exit cost in weeks. Most organisations have never written this down.
- Weeks 3–6 · Put a gateway in frontOne control point for every model call. Logging, redaction, routing, cost attribution. Highest return per euro in this entire talk.
- Weeks 7–10 · Prove portability onceMove a single real workload to a European provider. Not a pilot — a production workload. Measure what it actually cost.
- Weeks 11–13 · Set the SEAL requirementWrite a sovereignty level into your next AI procurement. Make suppliers answer it in writing.
Deliver this as an executive instruction, not a suggestion. Slow down. This is the takeaway they write in the notebook.
"None of these four need a business case. Three of them are someone's existing job. The first one is a spreadsheet — and I'd bet nobody in this room can produce it today."
The clouds aren't going anywhere. Your autonomy shouldn't live there.
Alessandro Vozza · Lovelace EngineeringPause. Then straight into the debate slide — do not fill the silence.
Sovereignty is not a product. It's a practice.
Sovereignty washing is the new greenwashing.
- Geographic residency without code transparency is a landlord model. You are renting your own sovereignty.
- Compliance without autonomy is theatre — a file that satisfies an auditor and changes nothing.
- Innovation without maintenance is a liability wearing a roadmap.
Open source is the floor, not the ceiling.
Forty seconds, and this is the last thing you say before you hand the room the microphone. Read the three middle lines slowly — they are the whole talk compressed, and each one is a test somebody in this room will fail on Monday.
"If you remember one slide, make it this one. Sovereignty is not something you buy — there is no product on the market that makes you sovereign, and anyone selling you one is doing to sovereignty what a decade of marketing did to sustainability. It's a practice. It's what you do every quarter, in procurement, in architecture, and in who you hire."
Landlord model is the line that lands hardest with this audience. Most of them have been sold EU region residency as sovereignty, and they already understand instinctively what it means to improve a property you do not own.
The last line is a deliberate callback to the maintenance slide. If someone noticed it the first time, they will notice it here, and it lands as a thesis rather than a repeat.
Then stop. Say nothing, advance to the provocations, and let them start.
Five minutes · your turn
One workload. Four boxes.
Not your portfolio — one real AI workload you actually run today. Back of your badge, phone, or just in your head.
Then: turn to the person next to you and compare. Two minutes. If you cannot fill in box 2, that is the finding — and it is the same finding almost everyone in this room will have.
Run it properly or do not run it at all. Say the instruction, then be quiet and let them work. Five minutes feels agonising from the stage and is about right from a chair. Do not narrate over it, do not fill the silence, and do not start early because the first thirty seconds look unproductive — they always do.
"Right, your turn. Pick one AI workload you actually run — not the portfolio, one. Four questions on the screen. Five minutes, and then compare with whoever is next to you. I'll be quiet."
Box 2 is the whole exercise. Almost nobody can answer it, and discovering that in a room full of peers is worth more than any slide I've shown. When you bring them back, ask for a show of hands on who filled in box 2 — it is the same show of hands as slide 5, and now they have proved it to themselves rather than taken my word for it.
Timing: this comes out of the discussion half, not the talking half. If you are badly over, cut the exercise and keep the provocations — but if you have the time, this is the part they will still be doing next week.
Bring them back with a hard "thirty seconds", then take three answers, then move to the provocations. Do not let the report-back run long; the point is that they did it, not that everyone shares.
Or start somewhere closer to home
Four questions, depending on which chair you are sitting in. Pick the one that makes you least comfortable.
- Founders & CEOsIf your model vendor tripled its price on Monday, who in your company would find out first — and how long before it reached you?
- CTOs & heads of engineeringHow many of your production dependencies are maintained by a single unpaid contributor?
- Finance, health, public sectorYour regulator asks you to demonstrate exit from your AI provider. What do you actually hand them?
- EveryoneIs European digital sovereignty achievable — or an expensive political narrative we will all have paid for by 2030?
Backup, not a scheduled slide. Use it if the exercise finishes early, if the provocations do not catch, or if you would rather run table discussion than one big-room argument.
"If none of my five provocations grab you, try one of these instead — pick whichever chair you're sitting in."
The segmentation is doing real work: a founder will not engage with a dependency-maintenance question, and a CTO will not engage with a pricing-escalation question, but each will engage hard with their own. In a room of eighty there are people in all four rows.
The last question is the honest one and the one most likely to produce a genuine disagreement, which is what you want. It is also provocation #1 from the next slide asked in a friendlier way — if it lands here, go straight to that slide and let it get sharper.
Five things I believe. Pick one and take it apart.
Twenty-five minutes. Call a number.
- Sovereign AI is protectionism with better branding, and Europe will lose the capability race by insisting on it.
- The EU AI Act deferral proves compliance pressure will keep slipping — so building for it now is wasted capital.
- Renting frontier models is fine; only the data layer ever needed to be sovereign, and everything else here is over-engineering.
- Nobody in this room can hire the platform team this requires, at any price, in this market.
- Grid capacity — not chips, capital, or regulation — is what actually decides who gets to do AI in the Netherlands.
This slide is the reason the session is 45 minutes. Leave it up for the whole Q&A so people always have something to grab.
Honest positions if nobody bites: I half-believe #1 — protectionism is a real risk and SEAL-4 is not achievable today. I strongly believe #5. #4 is the one that most often turns into a genuinely useful room conversation, because several people there are hiring against each other.
If the room is quiet: pick #4 yourself and ask who has tried to hire a platform engineer this year. That always opens it.
Fifteen seconds, and stop talking. Put it up, say the one line below, and let the room point their phones at the QR code. Silence here is the slide working, not the slide failing.
"Before the last slide — if anything today was interesting to you, this is in Amsterdam on the twelfth and thirteenth of November. AI for molecules and materials. Photograph the code now, because the next slide is just my contact details."
Leave it on screen for a genuine beat. People are slow to get their phones out, and the second half of the room only starts once the first half has.
Start with the inventory. Everything else follows from it.
If you write down every AI workload, its jurisdiction, and its exit cost, you will have done more sovereignty work this quarter than most organisations do in a year.
- Slides ams0.github.io/talks/beyond-the-clouds
- Contact alessandro@stackmasters.com
- LinkedIn /in/alessandrovozza
- Happy to argue about any of this at the drinks
Alessandro Vozza
Lovelace Engineering
Golden Kubestronaut
Disclosure: Lovelace Engineering consults for VOLT. Nebius is on the megawatt chart so that slide is not a single-vendor slide.
Keep it to fifteen seconds. The debate slide is the real close; this is who I am and how to reach me.
"That's me, that's the disclosure, and that's how to find me. Start with the inventory — everything else follows from it."
Sources
- Microsoft France testimonyFrench Senate inquiry into digital sovereignty, 21 July 2025 (The Register, SDxCentral)
- AWS European Sovereign CloudAmazon press release, 15 January 2026; InfoQ analysis
- Trump v. Slaughter · EDPB letterUS Supreme Court, 29 June 2026; EDPB to Commissioner McGrath, 31 July 2026
- Latombe judgmentEU General Court, 3 September 2025 (IAPP)
- Digital AI OmnibusProvisional agreement, May 2026 (Gibson Dunn; DLA Piper)
- AI ActReg. (EU) 2024/1689 · in force 1 Aug 2024 · Art. 5, 50, 51–56 · penalties Art. 99
- Data ActReg. (EU) 2023/2854 · applicable 12 Sep 2025 · Art. 29 switching charges withdrawn 12 Jan 2027
- DORA · NIS2 · CRAReg. (EU) 2022/2554 (17 Jan 2025) · Dir. (EU) 2022/2555 · Reg. (EU) 2024/2847
- Cloud Sovereignty Framework · SEALEuropean Commission, 17 April 2026 — €180m awarded to Post, STACKIT, Scaleway, Proximus
- Cloud Sovereignty Framework documentEuropean Commission, DG DIGIT, Luxembourg — version 1.2.1, October 2025
- European cloud market shareSynergy Research Group — European providers 29% (2017) to 15% (2022), holding at 15%; press release 24 July 2025
- Market concentrationSynergy Research Group — Amazon, Microsoft and Google ~70% of the European market; SAP and Deutsche Telekom 2% each
- AI Gigafactories callEuroHPC JU, 30 July 2026 — bids close 12 November 2026
- Kubernetes AI Conformance · llm-dCNCF, March 2026 · KubeCon + CloudNativeCon Europe, RAI Amsterdam, 23–26 March 2026
- Vendor country of origin (77%) · local vendors (59%)Deloitte, State of AI in the Enterprise 2026, n=3,235, 24 countries
- Inference repatriationBroadcom Private Cloud Outlook 2026 (56%→41%); Cloudian survey, March 2026 (93%)
- VOLT · Nebiusw.media, DatacenterDynamics, The Tech Capital, 2025–2026
- H100 cost range ($0.21–$15.25)Wavect break-even analysis, EU, 2026. Curve shape is fixed-cost ÷ utilisation, anchored on those endpoints.
- Von der LeyenState of the Union address, European Parliament, 10 September 2025
- DraghiThe Future of European Competitiveness, European Commission, 9 September 2024
- Open-source maintenanceLog4Shell (CVE-2021-44228); Germany's Sovereign Tech Agency and EU-STF proposals on funding OSS maintenance
- Platform chokepointsGitHub access restrictions in sanctioned regions; Gitee and the OpenAtom Foundation as domestic-fork responses
- European governanceSovereign Cloud Stack · GAIA-X · Digital Commons EDIC
- Model openness tiersOpenEuroLLM; Mistral; Llama 4 and DeepSeek R1 licence and training-data terms
Backup slide. Only show if challenged on a number — then find the line and read it. Having this ready is worth more than using it.