The gist: Three-quarters of DACH companies embed digital sovereignty strategically, yet only 14 percent have an executable exit strategy from cloud hyperscalers, and just 3 percent can measure their actual sovereignty.
While the German government and politicians promise billions in investments in digital independence, a Lünendonk study paints a different picture: 75 percent of DACH companies have embedded digital sovereignty strategically, yet only 14 percent have an executable exit strategy from cloud hyperscalers.
The discrepancy is significant. Germany and France are announcing a joint definition of digital sovereignty by mid-2026, flanked by sovereignty summits, Franco-German initiatives for frontier AI, and twelve billion euros in investment commitments. In parallel, a different reality emerges in many management situations: DevOps teams continue to deploy on AWS Lambda because rapid containerization is required; sales leaders immediately adopt AI-driven lead-scoring solutions – regardless of where they are hosted. The problem is not new intention, but pragmatism under pressure.
According to the Lünendonk study, only 3 percent of surveyed DACH companies have any metrics to measure their actual sovereignty. A typical scenario: a CIO assumes that the ERP system runs in a German data center and production data remains on-premise. What goes unaddressed: marketing automation on AWS, sales database at Salesforce, HR software as US-American SaaS, and development environments in Azure – together accounting for over 60 percent of business-critical data. In the event of a DORA compliance review, it quickly becomes clear: no one has an overview of the whole picture. An exit strategy does not exist.
A significant risk factor is the US Cloud Act, which obligates American technology and cloud service providers to hand over requested data to US authorities – regardless of whether servers are in the US or elsewhere. This does not automatically make Microsoft, Google, and Amazon the wrong choice, but it does require deliberate decisions per workload. Four classification dimensions have proven helpful for guidance: (1) Data – personal, confidential, or business-relevant? (2) Regulation – BaFin, KRITIS, NIS2? (3) Dependency risk – proprietary lock-in? (4) Latency & availability – business-critical? Only on this basis can a reliable migration strategy be developed.
The central insight: digital sovereignty remains a lip-service commitment in many companies as long as technological dependence is not systematically captured, classified, and supported by concrete exit scenarios. The stronger regulatory requirements (DORA, NIS2) become, the more urgent this stocktake becomes.
Source: www.it-daily.net · Published 7 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.