July 2026 - Data Sovereignty | Multi Cloud

Digital Sovereignty by Design: Rethinking Security, Cloud, and AI in Europe

Digital sovereignty must be designed in from day one. plusserver CEO Dr. Marc Wilczek on security by design, multi-cloud reality, and AI adoption in Germany.

Digital Sovereignty by Design: Rethinking Security, Cloud, and AI in Europe-web

© ismagilov| istockphoto.com

Digital sovereignty will not be achieved by patching problems after the fact – it has to be designed in from day one. Building on the panel discussion on “Future Connectivity” at the eco Interaction Day 2026, this article explores why security and compliance must become design principles, how businesses can master today’s fragmented IT landscapes, what really drives AI adoption in the German SMEs, and where policymakers need to act so that Europe’s digital economy can scale on its own terms.

Security is a design principle, not a patch

For too long, security has been treated as something to be added at the end – a patch applied once a product is already live. That approach was never ideal; today, it is untenable. Attack surfaces are expanding, and AI has fundamentally changed the tempo of the threat landscape. Techniques such as jailbreaks against AI systems demonstrate how quickly adversaries adapt and probe for weaknesses. If we only react to vulnerabilities as they appear, we will always be one step behind. The goal must be to stay ahead of the situation.

This is why security by design and SecDevOps are not buzzwords but practical guidelines. Security has to be embedded throughout the software development lifecycle and reflected in the IT architecture from the very first sketch, with development, operations, and security working as one team rather than as rigid process chains.

The same logic applies to compliance. Regulations such as the EU AI Act should not be read as a bureaucratic hurdle to be cleared shortly before an audit. It is far more productive to treat regulatory requirements as essential design criteria from day one. Companies that build compliance into their architecture gain something valuable in return: trust – and in digital markets, trust is a hard currency.

The multi-cloud reality: fragmented by default

When we talk about cloud strategy, we should start from how customers actually operate. Most of them do not live in a tidy single-cloud world. They work in a fragmented landscape, using a variety of clouds as landing zones for different workloads and specific use cases: hyperscalers for some applications, European providers for sensitive data, private clouds and on-premises systems for legacy or latency-critical workloads.

This fragmentation is reinforced by broader market dynamics. As I noted in an interview marking my first 100 days as CEO, companies are grappling with strained supply chains, rising costs, and increasing regulatory pressure on one side, and the accelerating adoption of AI solutions on the other. Rather than investing in their own data centers and scarce specialists, many German companies now look for managed infrastructure and precisely tailored cloud and AI solutions – provided these preserve control and sovereignty over their data.

Our collective task as an industry is therefore not to preach consolidation for its own sake, but to help customers run these mixed system landscape securely, efficiently, and in line with their compliance obligations. Hybrid and multi-cloud setups are not transitional phenomena on the way to some final state – they are the operating model of the foreseeable future.

Open source plays a central role in making this work. I would hesitate to call it a gamechanger, because that implies something revolutionary that has yet to arrive. Open source is a living reality: OpenStack and other frameworks already form the fundamental basis of modern cloud environments. This approach is also reflected in our long-standing commitment to European cloud initiatives. As a founding member of Gaia-X, we at plusserver have been involved since its inception. Gaia-X is not about creating a single European cloud, but about establishing common standards that enable interoperable, trustworthy cloud ecosystems while allowing organizations to retain control over their data and workloads. We also co-initiated the Sovereign Cloud Stack (SCS), an open, community-driven foundation for sovereign cloud infrastructure. For digital sovereignty, this matters enormously. Open technologies keep exit doors open, enable interoperability across providers, and help avoid the kind of vendor lock-in that quietly erodes a company’s freedom to act.

AI adoption is a question of DNA, not industry

The debate about AI in Germany often gets stuck at the level of abstraction. The reality on the ground is more encouraging – and more concrete. In the healthcare sector, voice-to-text solutions are already digitizing doctors’ visit notes. In industry, predictive maintenance helps manufacturers detect anomalies before machines fail. These are not pilots on slide decks; they are productive systems delivering measurable value today.

What separates the companies that implement AI successfully from those that merely discuss it is not their sector. It is the DNA of the organization – above all, the inventive spirit and technological understanding of its leadership. Where management genuinely engages with technology, use cases are identified, funded, and scaled. Where it does not, even the best tools gather dust. For the SMEs, this is good news: successful use of AI is not the privilege of any particular industry. It is a leadership decision.

Digital sovereignty needs deep pockets – and smarter procurement

Digital sovereignty – the ability of companies and public institutions to retain control over their data, technologies, and digital infrastructure – does not emerge in a political vacuum. Growing regulatory requirements, the rising strategic importance of digital infrastructure, and the current geopolitical situation have moved it from a niche topic to the center of the European debate. If Europe wants genuine digital sovereignty, two structural problems need to be addressed.

The first is capital. Europe has no shortage of intellectual power, research excellence, or entrepreneurial talent. What it lacks are the deep pockets required in the scaling phase. Time and again, promising European companies reach the point where they need serious growth capital – and find it only from American venture investors. The result is a familiar pattern: technology conceived in Europe ends up scaling, and creating value, elsewhere. We need funding instruments that allow European champions to scale from Europe.

The second lever is the public procurement. The state should lead by example in its tendering and award procedures. Today, contracts too often go to the lowest bidder – the proverbial “cheap jack.” Instead, public tenders should systematically reward providers that have committed to high compliance and digital sovereignty standards. Public demand shapes markets: if governments buy sovereign, secure, and compliant solutions, they create exactly the scale that European providers need to grow.

Staying ahead of the situation

Whether we look at security, cloud architecture, AI adoption, or industrial policy, the underlying principle is the same: act by design, not by reaction. Companies that embed security and compliance from the outset, that manage their multi-cloud reality deliberately, and that treat digitalization as a leadership task will stay ahead of the situation. And if policymakers support that ambition with growth capital and smarter procurement, digital sovereignty in Europe can move from aspiration to everyday practice.

 

📚 Citation:

Wilczek, Marc. (July 2026). Digital Sovereignty by Design: Rethinking Security, Cloud, and AI in Europe. dotmagazine. https://www.dotmagazine.online/issues/building-the-internet-of-tomorrow-2026/digital-sovereignty-security-cloud-ai

 


Dr. Marc Wilczek is CEO of plusserver, a leading provider of sovereign cloud and AI infrastructure headquartered in Germany. With operations, teams, and data centres located exclusively in Germany, plusserver supports companies in modernising their IT and cloud landscapes while safeguarding digital sovereignty and ensuring the secure, compliant use of AI. Dr Wilczek's expertise spans cloud transformation, IT security, and regulatory compliance, and he regularly shares his perspective on how European companies can reduce dependency on non-European providers and build resilient, future-proof digital infrastructures.

 

Digital sovereignty means retaining control over data, technologies, infrastructure, and critical digital dependencies. In this dotmagazine article, published by eco – Association of the Internet Industry, Dr. Marc Wilczek, CEO of plusserver, argues that sovereignty must be built into security, cloud, and compliance decisions from the outset.

Adding security or regulatory safeguards after a system has been deployed creates avoidable risks and costs. Dr. Marc Wilczek of plusserver explains in dotmagazine, published by eco – Association of the Internet Industry, that security by design, SecDevOps, and early compliance planning help companies reduce vulnerabilities and build trust.

Many companies use different cloud environments for different workloads, including hyperscalers, European providers, private clouds, and on-premises systems. In his dotmagazine article, published by eco – Association of the Internet Industry, Dr. Marc Wilczek of plusserver describes this fragmented landscape as a long-term reality that requires secure management, interoperability, and clear compliance controls.

Public authorities can support European digital providers by evaluating tenders on more than price alone and giving greater weight to security, compliance, and sovereignty standards. Dr. Marc Wilczek, CEO of plusserver, argues in dotmagazine, published by eco – Association of the Internet Industry, that smarter procurement can create demand, scale, and growth opportunities for European providers.

 

Please note: The opinions expressed in articles published by dotmagazine are those of the respective authors and do not necessarily reflect the views of the publisher, eco – Association of the Internet Industry.