SovereigntyEurope's missing compliance layer
Europe is building sovereign payments and sovereign AI. The system that reads its own regulation still runs on foreign software.
Essays on who gets to interpret European law, and why the infrastructure that reads a regulation is a question of sovereignty, not just software.
Written in Berlin · processed and hosted in the European Union
Compliance GuidesA search query led me here: someone drowning in DPIA templates. So let me actually answer them.
Compliance GuidesWhat a compliance spreadsheet cannot hold as a data structure, the signals it is time to move off it, and how to migrate one regime at a time.
Compliance GuidesA DPIA is required before processing that is likely to result in a high risk to people’s rights. Here is the threshold, the three automatic triggers, what the assessment must contain, and when you must consult the regulator.
Compliance GuidesThere is no single price, cost is driven by how many regimes, entities and jurisdictions you cover. Here are the real drivers, the common pricing models, and what to compare the number against.
Compliance GuidesIf you manufacture outside the EU and sell into it, three regimes can reach you: NIS2, the Cyber Resilience Act, and your customers’ supply-chain requirements. Here is which one applies.
Compliance GuidesThree ways to handle EU regulatory requirements: external consultants, an in-house team, and compliance software, with an honest comparison of where each one wins.
Compliance GuidesCompany owners outside Europe are sure EU law does not touch them because they have no EU office, and they are wrong. GDPR, the AI Act, DORA, and the product rules can all apply when you target the EU market. Here is what each one asks.
Compliance GuidesThe EU AI Act applies if you develop, place on the market, or deploy AI systems that touch the EU. Your requirements scale with the risk tier, here are the four tiers and what each one requires.
Compliance GuidesNIS2 applies to medium-sized and larger entities in a defined list of essential and important sectors, plus some entities regardless of size. Here is how to check whether you are in scope, sector first, then size.
RegulationA US ruling on who controls the FTC has quietly unsettled the legal basis for moving European data across the Atlantic.
RegulationA US ruling on who controls the Federal Trade Commission has quietly removed a load-bearing assumption beneath every transfer of European data to the United States.
Compliance GuidesThe prospects who raise DORA with me usually think it does not reach them, and they are usually wrong. Two tests decide it, and here is what it requires once you are in scope.
ArchitectureChecking a draft contract or a live incident against European law by running it through a foreign AI transmits the full text to a provider under foreign jurisdiction. That is a disclosure, and it may be one you never learn about.
Compliance GuidesFounders, company owners and CEOs ask me this before every raise and every audit. Which EU rules apply depends on four things, and here is how I scope them.
SovereigntyThe 3 June package targets chips, cloud, and AI. It says almost nothing about the systems that interpret Europe’s own regulation.
SovereigntyA short set of questions that separates genuine digital sovereignty from an EU region with a sovereignty label, applied honestly to ourselves as well.
RegulationFor most companies, compliance still lives in a spreadsheet held together by one overworked person. It breaks in four predictable places.
ArchitectureThe industry standard is to pull a customer’s documents into the vendor’s cloud. For regulated European firms, that convenience is the exposure.
RegulationDORA made banks map every critical technology provider. Few have turned that discipline on the software they use to manage compliance itself.
GeopoliticsIn 2019 three of Europe’s largest economies built a mechanism to trade around US sanctions. Its near-total failure is the clearest lesson in dependency Europe has.
SovereigntyThe term is appearing on every European vendor’s website. Most uses describe where data sits, not who controls it.
ArchitectureFor fifteen years European data protection has asked where information is stored. Artificial intelligence has changed the question to where regulation is understood.