SovereigntyEurope’s missing compliance layer
Europe is building sovereign payments and sovereign AI. The layer that interprets its regulation still runs on foreign software.
Essays on who gets to interpret European law — and why the infrastructure that reads a regulation is a question of sovereignty, not just software.
Written in Berlin · processed and hosted in the European Union
Compliance GuidesThree ways to handle EU regulatory requirements — external consultants, an in-house team, and compliance software — with an honest comparison of where each one wins.
Compliance GuidesEU law reaches you even without an EU office. Which requirements apply when you target the EU market — GDPR, the AI Act, DORA, and product rules — and what each one asks of you.
Compliance GuidesThe EU AI Act applies if you develop, place on the market, or deploy AI systems that touch the EU. Your requirements scale with the risk tier — here are the four tiers and what each one requires.
Compliance GuidesNIS2 applies to medium-sized and larger entities in a defined list of essential and important sectors — plus some entities regardless of size. Here is how to tell if you are in scope.
RegulationA US ruling on who controls the FTC has quietly unsettled the legal basis for moving European data across the Atlantic.
RegulationA US ruling on who controls the Federal Trade Commission has quietly removed a load-bearing assumption beneath every transfer of European data to the United States.
Compliance GuidesDORA applies to EU financial entities and their ICT third-party providers. Two tests, a decision path, and what it requires if you’re in scope.
ArchitectureChecking a draft contract or a live incident against European law by running it through a foreign AI transmits the full text to a provider under foreign jurisdiction. That is a disclosure, and it may be one you never learn about.
Compliance GuidesA practical way to scope which EU regulations apply to your business — by sector, size, data, and activity — with a business-type-to-regulation map.
SovereigntyThe 3 June package targets chips, cloud, and AI. It says almost nothing about the systems that interpret Europe’s own regulation.
SovereigntyA short set of questions that separates genuine digital sovereignty from an EU region with a sovereignty label, applied honestly to ourselves as well.
RegulationFor most companies, compliance still lives in a spreadsheet held together by one overworked person. It breaks in four predictable places.
ArchitectureThe industry standard is to pull a customer’s documents into the vendor’s cloud. For regulated European firms, that convenience is the exposure.
RegulationDORA made banks map every critical technology provider. Few have turned that discipline on the software they use to manage compliance itself.
GeopoliticsIn 2019 three of Europe’s largest economies built a mechanism to trade around US sanctions. Its near-total failure is the clearest lesson in dependency Europe has.
SovereigntyThe term is appearing on every European vendor’s website. Most uses describe where data sits, not who controls it.
ArchitectureFor fifteen years European data protection has asked where information is stored. Artificial intelligence has changed the question to where regulation is understood.