Andrea Margiovanni .it
A railway switch in the middle of vegetation: two rusty tracks split in front of the viewer, one running straight ahead and the other curving left between the trees. On the right, the manual switch lever with its red signal disc.
Photo by Breaks Out (Pexels)
Home / All essays / Issue № 94

The Cost of Changing Your Mind

For years we looked for digital sovereignty in the provider's passport, the location of the data centre, the software licence. Those are fair questions that miss the decisive one: if we want to change our decision tomorrow, can we actually do it, and at what price? Sovereignty as a real option, and a way to count it.

Today, September 8, 2026, Mistral announced a €3 billion Series D at a post-money valuation of “more than €21 billion”, led by Samsung Electronics, with the EQT-managed Scaleup Europe Fund and PSG Equity as co-leads. A year ago, on September 9, 2025, it was a €1.7 billion Series C led by ASML, at €11.7 billion. Today’s announcement is not about better models. It is about a “sovereign AI layer”, about control over data, models, compute and systems in production. In 2026, the word sovereignty goes in the headline, and the vendor puts it there.

Three months earlier, on June 3, presenting the European tech sovereignty package, Henna Virkkunen delivered the line the papers ran with: “We want to be sure nobody has a kill switch”. The official press release is more composed: two legislative proposals, the Chips Act 2.0 and the Cloud and AI Development Act, an open source strategy, an energy roadmap, the goal of tripling European data-centre capacity in five to seven years, and “a single EU-wide framework to assess cloud and AI sovereignty”. On September 15 the targeted consultation on data sovereignty that accompanies the package closes. It asks companies which dependencies affect them, which obstacles they meet when moving data into Europe, which risks they see in third-country access to sensitive data.

These are the questions we have been asking for years, and they are questions about provenance. Where the data centre is. Where the provider is incorporated. Who owns the model. Under which jurisdiction the company holding the data operates. In the colophon of this site, under sovereignty, I wrote “who has their hand on the kill-switch”, and I stand by it: these are important questions, in some sectors decisive ones. But I suspect they do not describe the most important property of sovereignty, and that asking only those is making us mistake something measurable for something that merely resembles it.

A company can use exclusively European technology and be deeply dependent. Another can use American technology and keep a remarkable degree of autonomy. The difference lies in a question far simpler than all of the above: if I want to change my decision tomorrow, can I actually do it? Not in theory. Not because the contract has a data export clause. Not because a compatible endpoint exists. Economically, technically and organisationally. Sovereignty might be precisely this: the capacity to keep real options after having chosen.

Provenance and Sovereignty Are Not the Same Thing

The intuitive reasoning is linear. European provider, more sovereignty. American provider, less. And it is understandable, because a European operator does reduce some categories of risk: the extraterritorial reach of someone else’s law, geopolitical dependency, access from third jurisdictions, industrial concentration. The concentration numbers are well known. According to Synergy Research Group, European providers hold 15% of the European cloud market, down from 29% in 2017, while Amazon, Microsoft and Google together hold 70%; the two largest Europeans, SAP and Deutsche Telekom, sit at 2% each, in a market worth €61 billion in 2024. The Commission estimates that the Union depends on third countries for over 80% of key digital products, services, infrastructure and intellectual property. Anyone buying public or critical infrastructure has every reason to look at the passport.

But the provider’s passport still says nothing about another fundamental property: what it costs to leave.

Imagine an entirely European cloud. The data is in Europe, the company is European, the contract is governed by European law. The product, however, rests on proprietary APIs, on a database that exports only in its own format, on an identity model with no equivalent outside, on managed services nobody else offers in the same shape, on price lists that reward volume and punish whoever scales down. We are certainly more European. It is far less obvious that we are more sovereign. We have moved the jurisdiction risk and left the exit cost intact, or raised it.

The opposite objection deserves the same respect, because it would be too convenient to conclude that provenance therefore does not matter. It matters a great deal. An infrastructure entirely dependent on entities subject to another legal order carries risks that no good API removes. Sanctions exist. Export restrictions exist. Government orders exist, and the US CLOUD Act, which Virkkunen cited on that same occasion as the reason American providers will struggle to reach the top tier of the new European framework, is a law in force, not a hypothesis. The concentration of capital and compute exists. The point is not to replace geographic sovereignty with portability. It is to understand that neither is enough on its own. You can have territorial control without freedom to exit, and technical portability without jurisdictional control. Real sovereignty is probably multidimensional, and the European debate has spent ten years measuring a single dimension.

Three Pieces of One Thing

Three very different stories, read together, draw the shape of the problem.

The first is Mistral, and it is the capital piece. With today’s three billion, the rounds announced since 2023 add up to more than five and a half billion euros, and Mistral Compute, announced with NVIDIA on June 11, 2025, turns the first tranche of that money into silicon: 18,000 Grace Blackwell systems in a data centre in the Essonne. A European lab able to raise billions matters, but not for the reason one keeps hearing. Not because a French passport automatically makes a model sovereign: a model is exactly as sovereign as the contract governing it and the customer’s ability to do without it. It matters because it increases the number of industrially plausible options. If only one supplier can meet a requirement, we can formally choose not to use it, but that is not a real choice if declining means giving up the capability. An alternative becomes politically interesting only when it gets good enough to be chosen without turning the choice into a symbolic sacrifice. That is what capital does. It does not produce sovereignty directly. It funds the possibility that an alternative exists.

The second is IRIS², and it is the distribution piece. The twelve-year concession with the SpaceRISE consortium, that is SES, Eutelsat and Hispasat, was signed on December 16, 2024, at a cost then estimated at €10.6 billion, €6.5 billion of it public. On August 7, 2026 the implementation agreement took the constellation to 348 satellites, 330 in low orbit and 18 in medium orbit, with first launches planned for 2029 after a schedule that had slipped more than once. Today nothing is in orbit and no company can buy a single megabit of IRIS². A European constellation is a strategic asset, but it becomes a real option for a business only when someone turns it into purchasable connectivity: a contract, an SLA, support, an invoice, an integration with the network the company already runs. This is the step the European debate most often skips. We have a very strong tradition of funding infrastructure, research and standards, and a weak one in the commercial last mile, the one that lets a CTO put that technology into a decision matrix next to the others. Sovereignty that never reaches procurement remains potential capacity. It exists, but it cannot be chosen.

The third is Oracle, and it is the contract piece, the most interesting of the three. Suppose the alternatives exist and the customer wants to switch. Technically they could. But the contract makes the choice economically irrational. Oracle’s policy on licensing in cloud environments, dating from January 2017, states that on AWS and Azure two vCPUs count as one processor and the core factor table does not apply: the same database, moved from the customer’s data centre or from Oracle Cloud to a competing cloud, can require twice the licences. Since January 23, 2023, Java SE is priced per employee, $15 a month each below a thousand, and the count includes contractors and consultants, not the people who use the software. The support policies forbid keeping support on a subset of the licences in an order, reprice the remaining ones at list if part is cancelled, and charge 150% of the last annual fee to come back. And since June 2021 Oracle Support Rewards knocks at least 25 cents off the support bill for every dollar spent on Oracle’s cloud: the discount exists for as long as you stay. None of these clauses forbids leaving. Each shifts the arithmetic so that staying always looks like the prudent decision. The technical possibility still exists. The economic one does not. On September 1, 2026, Reuters reported that Oracle’s licensing practices are “on the radar” of the Commission, which is gathering information from third parties; the Commission itself stresses there is no formal investigation. The precedent is two months old. On July 9 the Commission made SAP’s commitments binding for ten years on support for its on-premises ERP: customers will be able to split their estate into parts with different providers and support levels, terminate unused licences in defined cases, and the reinstatement fees charged to those returning after a period away are abolished. None of those clauses forbade leaving either. Teresa Ribera said the decision “should serve as a warning against practices with similar effects in the cloud markets, where customers are increasingly moving”.

And when the arithmetic is not enough, the termination notice arrives. Broadcom, having bought VMware, ended perpetual licences on December 11, 2023 and moved everything to subscription; CISPE, the association of European cloud providers, documented price increases of up to twelve times and terminations with a few weeks’ notice. The most instructive case is Dutch. Rijkswaterstaat, the infrastructure agency, held perpetual licences; the subscription bundle would have raised its cost by 85%, and in the meantime the agency could not migrate in time. On June 27, 2025 the District Court of The Hague ordered Broadcom to keep providing support for up to two years, at a price set by the judge and with a penalty of €250,000 a day, on reasoning worth a treatise: the vendor breaches its duty of care if it does not put the customer in a position to leave. A judge had to reopen, by court order, the path between one choice and the next.

This is where the European interest in licensing, cloud switching, the Data Act, the DMA and competition starts to look like one policy rather than four. The Data Act, applicable since September 12, 2025, devotes a whole chapter to switching between data processing services: Articles 23 to 31 require providers to remove the technical, contractual and organisational obstacles to switching, set a maximum notice period of two months and a thirty-day transition period the customer may extend once, and in Article 29 establish that from January 12, 2027 switching charges, egress included, can no longer be billed, after three years in which they may cover only direct costs. Google dropped egress fees for departing customers on January 11, 2024, AWS on March 5, citing the Data Act explicitly, Microsoft on March 13; Oracle did not, as the UK competition authority noted. That same CMA, closing its cloud market investigation on July 31, 2025, called egress fees “a key commercial barrier” to switching and found that Microsoft’s licensing practices reduce competition between clouds; on March 31, 2026 it accepted commitments from AWS and Microsoft to make egress on exit free for at least 180 days. And on June 25, 2026 the Commission informed Amazon and Microsoft of its preliminary view that AWS and Azure should be designated gatekeepers under the DMA despite not meeting the quantitative thresholds, because they “appear to benefit from lock-in effects and high switching costs” and because their portfolio of AI tools “has become a decisive factor in cloud procurement”. Building alternatives is not enough. The path leading to them has to stay passable, and the path is governed by contracts.

A More Useful Definition of Lock-In

We usually say: I am locked in because leaving is hard. True, and imprecise. A more useful definition might be this: you are locked in when the cost of exercising an alternative is high enough to make your freedom of choice mostly theoretical.

The cost can be technical, economic, cognitive, contractual, organisational. It is usually a sum of all five, and the one that weighs most is rarely the one visible in the contract. This definition explains why lock-in does not coincide with proprietary software. An open source system can create enormous operational lock-in, if nobody in the company still knows how to run it outside the configuration it grew up in. A proprietary SaaS with excellent APIs, complete export and standard formats can produce relatively little. The licence says what I have the right to do. The exit cost says what I am able to do.

Sovereignty Is a Dynamic Property

This is perhaps the most important conceptual step, and the most uncomfortable for anyone doing architecture. We cannot establish once and for all that an architecture is sovereign, because sovereignty changes over time while the architecture stands still.

A vendor can change prices, and anyone running VMware has known that since December 2023. A model can be retired: OpenAI removed GPT-4o from ChatGPT on February 13, 2026, Anthropic retired Claude 3 Opus on January 5, 2026, Google shut down Gemini 1.5 Pro on September 29, 2025, and on September 1 GitHub retired six models from Copilot as ordinary lifecycle, as I described in You Can’t Export the Function. A licence can change: HashiCorp moved Terraform under the Business Source License on August 10, 2023, Redis left the BSD licence on March 20, 2024 and then added the AGPL on May 1, 2025, by which time the Valkey fork had already taken a share of its users. A project can lose its maintainers, or worse, gain one it should not have: the xz backdoor, CVE-2024-3094, discovered by Andres Freund on March 29, 2024, had been planted by a co-maintainer who earned the trust of an exhausted maintainer within about a year. A company can be acquired: IBM closed its acquisition of HashiCorp on February 27, 2025. An access can be shut off by a clause between third parties, as happened to Cursor with OpenAI’s models. A new regulation can change the relative cost of the alternatives, and the Data Act is doing that right now.

So the question is not only how much control we hold today. It is how many realistic options we are preserving for tomorrow. The first can be photographed in an audit. The second can only be measured by trying.

Optionality as an Architectural Property

Here the reasoning turns technical, and this is the point where it stops being a matter for conferences.

Architecture should not try to eliminate every dependency. That would be impossible, and probably inefficient. It should decide which dependencies deserve to stay reversible. A commodity service can be tightly coupled, if replacing it is cheap. A strategic function requires a different kind of attention. For those, and only those, you pay for the things that buy future optionality: open formats for the data that matters, standard protocols where they exist, exports that have been tried and not merely promised, an abstraction layer over the model where it is needed and not everywhere, vendor-independent evaluations, infrastructure described as code and therefore reproducible elsewhere, backups restored outside the provider at least once, documentation that outlives the person who wrote it, enough in-house skill not to have to ask permission, a second source already qualified for the components that cannot stop. Not because “vendor-neutral” is always better. Because these things buy the right to change your mind.

And they cost. This should be said plainly, because the sovereignty conversation tends to pretend otherwise. A perfectly portable architecture costs. Keeping two providers costs. Giving up the best proprietary feature costs. Testing a fallback costs. Keeping skills in-house costs. Running an exit test periodically costs. Exactly as backups, disaster recovery, redundancy and cyber insurance cost. They are deliberate inefficiencies that buy resilience, and nobody calls them waste. So we should not maximise sovereignty. We should decide how much we are willing to pay to keep it, dependency by dependency.

The financial sector, which usually gets there first because it has already paid for its crises, has written this into a rule. DORA, applicable since January 17, 2025, requires in Article 28(8) that financial entities put in place exit strategies for ICT services supporting critical or important functions, with plans that are “comprehensive, documented and sufficiently tested”, and the EBA guidelines on outsourcing had asked for the same since 2019. It does not say “use European providers”. It says: prove you can leave.

An Option Premium

At this point the discussion stops being ideological and becomes a management decision, the kind taken with a spreadsheet rather than a flag.

For every important dependency you can ask four questions. How much value does it give us. What is the probability we will have to replace it within the horizon we care about. What would replacing it cost. What does it cost, today, to keep a workable alternative alive. It is almost an ordinary financial appraisal, and finance already has a name for the object: call it an option premium. We pay a small amount today to keep the right, not the obligation, to change our decision tomorrow.

The metaphor is more precise than it sounds. Stewart Myers introduced it in 1977, in a paper on corporate debt, calling “real options” the future investment opportunities a firm owns and may exercise or let lapse; Dixit and Pindyck turned it into a book in 1994, Investment under Uncertainty, and the central lesson is that under uncertainty flexibility has a calculable price, and whoever ignores it systematically undervalues the cost of committing. An option does not oblige you to do anything. It guarantees you the right to do it on known terms. A good sovereign architecture works the same way. It does not mean “we must migrate off AWS”. It means “we can, if it becomes necessary, and we know how long it takes and what it costs”. It does not mean “we must use only European models”. It means “we can replace the current model if our balance between quality, price, risk and jurisdiction changes”. It does not mean “we must self-host everything”. It means “we own enough data, specifications and skills not to be completely dependent on the current host”. Sovereignty is not the continuous exercise of independence. It is owning the practicable right to exercise it.

Two Companies

The cloud makes the difference visible to the naked eye.

The first company uses a European cloud. Everything is deeply integrated with the provider’s proprietary services. Nobody has ever attempted a migration. The infrastructure cannot be reproduced elsewhere, because it was built in the console, by hand, over five years. Backups exist, but they have never been restored outside the provider. The contract has a data export clause nobody has ever read to the end.

The second uses AWS. The core data lives in open formats. The infrastructure is declarative and versioned. The proprietary dependencies are known and counted: there are seven, they fit on one page, and next to each is written what would replace it. There is an exit plan. A couple of critical workloads are periodically run elsewhere, to see what breaks.

Which of the two is more sovereign? The answer is not obvious, and that is exactly the point. The first has solved the jurisdiction dimension and left the exit dimension open. The second has done the reverse. If sanctions, a foreign court order or a diplomatic crisis are the risk that keeps the board awake, the first is right. If the risk is a price list that doubles, a product that gets retired, an acquisition that changes the rules, the second is right. A serious architecture today should be able to answer both, and most answer neither: they use the provider the market handed them and call the data-centre region sovereignty.

There is a well-known example of an exit carried through to the end, and it is useful precisely because it has nothing to do with Europe. 37signals, the company behind Basecamp and HEY, announced its departure from AWS on October 19, 2022, bought about $700,000 of Dell servers, moved every application onto its own hardware by June 2023 and watched its cloud bill fall from $3.2 million to $1.3 million a year in 2024; the last piece, some ten petabytes on S3, left by the contract expiry of June 30, 2025 for storage of its own. David Heinemeier Hansson puts the savings at more than ten million over five years, and those are his figures, not independently verified. It is not a model to copy: few have that load profile, and almost nobody has a founder willing to publish the numbers. But it proves something the European debate takes for granted without ever checking: that leaving a hyperscaler is a project with a beginning, an end and a cost, not a metaphysical condition.

AI Makes Everything Harder

With foundation models the problem goes beyond data and infrastructure, and I have followed it through two essays this one closes as a triptych. In The Lock-In Won’t Be in the Data Anymore I argued that the next lock-in lives in the state a system accumulates while working for us. In You Can’t Export the Function I conceded that even that state could be portable, and showed that the process can still get worse, because the model is not a neutral interpreter of the process but a part of it.

We can own prompts, specifications, documents, memory, tools, evaluations, and still depend on one particular cognitive capability. One model reads a specification better. Another needs more supervision. One costs a fifth. One can run on-prem. One gets retired. One changes its usage policy. Sovereignty over AI therefore requires one more kind of optionality, which I would call function portability: being able to change endpoint is not enough, you need to know whether the process keeps working once you have.

That is why evaluations are instruments of sovereignty, and not only of quality. If I own a battery of tasks representative of real work and acceptance criteria independent of the model, I can run it against GPT, against Claude, against Mistral, against an open-weight model running on a machine I control. I can measure the loss. I can decide whether it is acceptable. I have an option. If all I know is that “it works well with Claude”, I do not own the definition of the capability: I depend on whoever executes it. The ability to measure the alternative is part of the ability to choose it. And this is where the fact that Mistral Large 3 and the Ministral 3 models shipped under Apache 2.0 on December 2, 2025, followed by Mistral Small 4 in March 2026, matters less as a flag and more as an executable plan B: weights you can download today and run on hardware you control, measuring on the same tasks how much you lose.

Open Source Is a Right Too, Not a Capability

Open source is often used as a synonym for sovereignty, and the European Open Source Strategy presented on June 3 restates the equation. But a permissive licence guarantees above all a right. It does not guarantee the capacity to exercise it.

You can have the right to fork a project and own none of the maintainers, the skills, the release infrastructure, the community, the budget. Formally you are free. Operationally you are not. OpenTofu and Valkey exist because the Linux Foundation and companies with engineers to assign stood behind them, and in Valkey’s case those companies are called AWS, Google and Oracle: the fork was paid for by those with the most to lose. The great majority of projects that change licence or lose their maintainer do not produce a viable fork. They produce an exposure. The Strategy itself concedes as much when it promises to invest in “the long-term maintenance and security of Europe’s open-source digital infrastructure”: an admission that the right already exists and the capacity does not. Once again, legal freedom and real optionality do not coincide.

A Politics of Optionality

Seen together, the European instruments look like separate initiatives, born in different directorates-general with different vocabularies. The Data Act and the DMA. The sovereignty framework of the Cloud and AI Development Act. The AI Act. EuroHPC’s AI Factories, nineteen of them, and the AI Gigafactories, up to seven, with a call open from July 30 to November 12. Private capital in Mistral. STACKIT and OVHcloud, which exist because someone buys. IRIS². The Open Source Strategy. And procurement: on April 17, 2026 the Commission awarded its own first sovereign cloud contract, €180 million over six years, to four European groupings, among them STACKIT, Scaleway, OVHcloud with Post Telecom and CleverCloud, and Proximus with S3NS, Clarence and Mistral, using its own Cloud Sovereignty Framework with five levels, SEAL-0 to SEAL-4, and SEAL-2 as the minimum.

There is a detail in that tender worth more than many speeches. The Cloud Sovereignty Framework the Commission used to score the bids measures eight objectives. The fourth, operational sovereignty, lists as its first factor “ease of migrating workloads or integrating with alternative EU-controlled solutions without vendor lock-in”, and weighs 15% of the score; legal and jurisdictional sovereignty weighs 10%, with the note that the procedure already contains other safeguards on that front. Whoever wrote that grid put the exit cost among the award criteria. They do not call it optionality, but they count it.

All these instruments can be read through a single question: how do we increase the number of alternatives a European actor can realistically exercise?

Capital builds the alternatives. Infrastructure makes them reachable. Standards lower the cost of switching. Law stops some incumbents from raising it artificially. Procurement creates the demand that keeps alternatives alive after the press release. It is a politics of optionality, even if no document calls it that.

And perhaps it is a better European definition of sovereignty than autarky. Europe will not necessarily produce every chip, every model, every database, every cloud service. And it probably should not try: the June 3 release says so in its own way when it promises to keep “most of our market open to like-minded partners”. The serious question is whether it can build an economic system in which no critical dependency becomes irreversible. That is a far more realistic goal, and far more consistent with a continent integrated into global supply chains, with no interest whatsoever in leaving them.

An Exit Budget

For a small software house this philosophy becomes concrete fast, because we do not have the luxury of discussing it in the abstract. When we choose an important dependency, at Oltrematica we ask the questions everyone asks: what it costs today, how good it is, how fast we can get it into production. We add one: what it costs to change our mind. And above all: are we doing anything today that makes that cost needlessly higher tomorrow?

Sometimes the answer is yes, and it is worth it. Perfectly legitimate. Sovereignty does not mean avoiding lock-in at any cost. It means taking it on knowingly, with a date next to it. We are rewriting a product from Python to Laravel, and halfway through I can tell you what an unplanned exit costs: months, not weeks, and a re-engineering that appeared in no estimate when the first choice was made.

A practical formula I am trying to use is a maximum exit budget for every strategic component, without the false precision of euros. Low: replaceable in days, with a known procedure. Medium: weeks, a migration already done at least once, perhaps in staging. High: months, re-engineering required, skills to buy. Critical: no workable alternative currently exists. Then one question, to be asked in a meeting with the people who sign: are we aware of which components are classified Critical, and did we decide they should be? That is already a far more useful form of governance than “let’s avoid vendor lock-in”, a sentence everyone approves and nobody can violate.

The most interesting thing is that at this point sovereignty and resilience converge. Business continuity, the kind in ISO 22301, asks: what happens if this resource disappears? Sovereignty asks: can we choose to stop depending on this resource? They are almost the same question seen from two directions, one starting from the incident and the other from the will. The architecture needed to answer is often the same, and whoever already has a continuity plan has done half the work without calling it sovereignty.

Saying No After Having Said Yes

Before the choice we almost always have freedom. We can compare vendors, run a procurement, negotiate, choose. It is the moment when everyone feels sovereign, and indeed it is the moment the word gets said most.

The interesting problem begins afterwards. After five years of data, integrations, skills, workflows, contracts, habits. That is where we find out whether the initial freedom was real or was only the freedom to enter. Sovereignty is not measured at the moment we pick a supplier. It is measured five years later, when we try to pick another.

For years we have looked for digital sovereignty in the most visible places. In the provider’s passport. In the location of the data centre. In the software licence. In the country where the model is trained. These are important properties, and the consultation closing on September 15 is right to ask about them. But perhaps the decisive question is less about identity and more concrete. What happens if we change our mind tomorrow? Can we take the data with us? Can we rebuild the service? Can we change the model? Can we shrink the contract? Can we find the skills? Can we keep working during the transition? Do we know how much we will lose?

If the answer is yes, we own something more important than independence: we own a choice. If the answer is no, the fact that the provider is European, American, open source or proprietary changes some categories of risk, but does not remove the dependency.

I do not think sovereignty is the absence of dependencies. Modern economies do not work that way, and ours less than most. It is the capacity to stop a dependency from becoming destiny. The three billion that went into Mistral today create an alternative. IRIS² builds another infrastructure. The European switching rules try to keep the path between one choice and the next open. They are different pieces of the same political architecture, because an alternative that does not exist cannot be chosen, an alternative that cannot be reached is useless, and an alternative that costs too much to exercise exists only on paper.

Digital sovereignty, in the end, might simply be the economically credible capacity to change a decision. That definition has one advantage over the others: it can be measured. Not by asking how European our stack is. By asking how free we still are after having chosen it.

An alternative that costs too much to exercise is not an alternative. It is a line in a strategy document.

Key takeaways

  • Provenance and sovereignty are not the same. A European provider lowers the risks of jurisdiction, sanctions and third-country access, but says nothing about the cost of leaving. You can have territorial control without freedom to exit and technical portability without jurisdictional control: neither is enough alone, and the European debate spent ten years measuring one dimension.

  • Lock-in is the cost of exercising an alternative, not the licence. Oracle’s policies, the Broadcom termination halted by a Dutch court, the SAP commitments of July 9, 2026 and the preliminary DMA designation of AWS and Azure for “high switching costs” all say the same thing: contracts govern the path between one choice and the next, and European law is trying to keep it open.

  • Sovereignty is a real option and carries a premium. Open formats, declarative infrastructure, model-independent evals, backups restored outside the provider and periodic exit tests cost what a backup costs and buy the right to change your mind. A maximum exit budget per component, from Low to Critical, decided by the people who sign, beats “let’s avoid vendor lock-in” as governance.

Sources

  1. Mistral announces a €3 billion Series D led by Samsung Electronics, Mistral AI, 8 September 2026
  2. Mistral AI raises €1.7B to accelerate technological progress with AI, Mistral AI, 9 September 2025
  3. Europe unveils tech sovereignty package amid growing concerns over reliance on U.S. tech: 'We want to be sure nobody has a kill switch', CNBC, 3 June 2026
  4. Commission proposes tech sovereignty package to strengthen Europe's digital autonomy and resilience (IP/26/1187), European Commission, 3 June 2026
  5. Targeted consultation on safeguarding the EU's data sovereignty, European Commission, DG CNECT, 8 July 2026
  6. Strengthening Europe's Tech Sovereignty, European Commission, DG CNECT, June 2026
  7. European Cloud Providers' Local Market Share Now Holds Steady at 15%, Synergy Research Group, 24 July 2025
  8. NVIDIA Partners With Europe Model Builders and Cloud Providers to Accelerate Region's Leap Into AI, NVIDIA Newsroom, 11 June 2025
  9. SpaceRISE signs concession contract to deliver Europe's IRIS² connectivity network, SES, 16 December 2024
  10. ESA confirms kickstart of IRIS² with European Commission and SpaceRISE, European Space Agency, 16 December 2024
  11. European Union accelerating and reinforcing IRIS², European Commission, DG DEFIS, 7 August 2026
  12. Why Europe's IRIS² constellation is in trouble, Quilty Space, 30 May 2025
  13. Licensing Oracle Software in the Cloud Computing Environment, Oracle, January 2017
  14. Oracle Java SE Universal Subscription Global Price List, Oracle, 1 March 2023
  15. Oracle Software Technical Support Policies, Oracle, 17 August 2026
  16. New Oracle Support Rewards Program Helps Customers Accelerate Cloud Migrations While Reducing Software License Support Costs, Oracle via PR Newswire, 22 June 2021
  17. Oracle licensing practices on EU antitrust regulator's radar, source says, Reuters (via The Star), 2 September 2026
  18. Commission accepts binding commitments by SAP to address competition concerns about services for its popular business management software (IP/26/1554), European Commission, 9 July 2026
  19. VMware End Of Availability of Perpetual Licensing and SaaS Services, VMware by Broadcom, 22 January 2024
  20. Broadcom's brutal contract termination and imposition of prohibitive new licensing terms will decimate Europe's cloud infrastructure, CISPE, 19 March 2024
  21. Rechtbank Den Haag, ECLI:NL:RBDHA:2025:11349 (De Staat der Nederlanden / VMware, Broadcom), de Rechtspraak, 27 June 2025
  22. Regulation (EU) 2023/2854 (Data Act), Official Journal of the European Union, 22 December 2023
  23. Cloud switching just got easier: Removing data transfer fees when moving off Google Cloud, Google Cloud Blog, 11 January 2024
  24. Free data transfer out to internet when moving out of AWS, AWS News Blog, 5 March 2024
  25. Cloud services market investigation, Appendix N: Egress fees, free switching programmes, Competition and Markets Authority, 31 July 2025
  26. Cloud services market investigation: summary of final decision, Competition and Markets Authority, 31 July 2025
  27. Actions on cloud and business software through the UK digital markets competition regime, Competition and Markets Authority, 31 March 2026
  28. Commission reaches preliminary position that Amazon's and Microsoft's market leading cloud services should be designated under the DMA (IP/26/1444), European Commission, 25 June 2026
  29. Retiring GPT-4o and older models, OpenAI, 29 January 2026
  30. Model deprecations, Anthropic, 2026
  31. Gemini API release notes, Google AI for Developers, 29 September 2025
  32. HashiCorp adopts Business Source License, HashiCorp, 10 August 2023
  33. Redis Adopts Dual Source-Available Licensing, Redis, 20 March 2024
  34. Redis is open source again, Redis, 1 May 2025
  35. backdoor in upstream xz/liblzma leading to ssh server compromise, oss-security (Andres Freund), 29 March 2024
  36. HashiCorp officially joins the IBM family, HashiCorp, 27 February 2025
  37. Regulation (EU) 2022/2554 (DORA), Official Journal of the European Union, 27 December 2022
  38. Guidelines on outsourcing arrangements (EBA/GL/2019/02), European Banking Authority, 25 February 2019
  39. Determinants of Corporate Borrowing, Journal of Financial Economics, 5(2), November 1977
  40. Why we're leaving the cloud, David Heinemeier Hansson (HEY World), 19 October 2022
  41. Our cloud exit savings will now top ten million over five years, David Heinemeier Hansson (HEY World), 17 October 2024
  42. It's five grand a day to miss our S3 exit, David Heinemeier Hansson (HEY World), 26 March 2025
  43. Introducing Mistral 3, Mistral AI, 2 December 2025
  44. OpenTofu Announces General Availability, The Linux Foundation, 10 January 2024
  45. Linux Foundation Launches Open Source Valkey Community, The Linux Foundation, 28 March 2024
  46. EuroHPC Joint Undertaking launches AI Gigafactories call, EuroHPC Joint Undertaking, 30 July 2026
  47. Commission advances cloud sovereignty through strategic procurement, European Commission, 17 April 2026
  48. Cloud Sovereignty Framework, Version 1.2.1, European Commission, DG Digital Services, October 2025
  49. ISO 22301:2019, Security and resilience, Business continuity management systems, Requirements, ISO, 30 October 2019

The author

Andrea Margiovanni

I help public bodies and private organizations read their own infrastructure dependencies. Digital sovereignty is a lattice, not a flag; and it is measured more on contracts than on speeches.

See the guide
© 2026 Andrea Margiovanni Made with care, by hand