On 1 October 2026, Mathias Rumbold from ForgeOne had the opportunity to exchange views with Karoline Angerer at the Federal Chancellery on technological sovereignty, European IT infrastructure and the role of Austrian and European companies.

The discussion was deliberately technical and practical. What made it valuable was that it did not have to reduce the topic to buzzwords such as cloud, data or artificial intelligence, but could follow the different layers of modern IT infrastructure.

The central idea of the conversation: digital sovereignty does not begin with data, cloud or AI. It starts much earlier, with the technological foundation on which these systems run.

Sovereignty Is More Than Data Location

In many discussions, digital sovereignty is first understood as a data question: where data is stored, who may access it and which jurisdiction applies. These questions matter. But they are not enough if critical infrastructure is to remain controllable over the long term.

It is just as relevant which hardware systems run on, where firmware and central components come from, which operating systems and platforms are used and which vendors, update paths, licensing models and distribution infrastructure operations depend on.

Technological sovereignty therefore does not mean having to develop every technology ourselves. It means having choice, control, portability, know-how and realistic alternatives, and being able to assess critical dependencies consciously.

The Full Technology Stack

The OSI model was used in the conversation as an illustrative example. Not because it is itself a sovereignty model, but because it shows that complex IT systems consist of several interdependent layers. Looking only at the upper layers makes it easy to miss dependencies in the foundation.

A holistic view therefore has to look from the foundation all the way to the application:

  • hardware and supply chain

  • firmware

  • operating system

  • virtualization and infrastructure

  • container and platform technologies

  • identity and access management

  • collaboration and communication

  • business applications

  • data

  • cloud services

  • artificial intelligence

Sovereignty at higher layers can only be assessed credibly if the underlying dependencies are not ignored. This affects technical architecture as much as operations, maintenance, migration, documentation and the question of whether European teams can continue operating systems independently when it matters.

European Context

On 3 June 2026, the European Commission presented a European Technological Sovereignty Package. It addresses semiconductors, cloud, artificial intelligence and open source, among other areas. This makes clear that technological sovereignty is not merely a data protection or cloud question, but a strategic capability to develop, control and operate critical technologies.

The Commission’s Cloud Sovereignty Framework is also particularly relevant. It assesses sovereignty across several categories, including strategic control, legal and jurisdictional control, data and AI, operational sovereignty, supply chains, technology, security, compliance and sustainability.

The implementation guidance also addresses the origin of physical components, firmware, the origin and control of software, open interfaces, portability, avoidance of vendor lock-in and the ability of European operators to operate and maintain systems independently. This supports the practical approach of not letting sovereignty begin only at data storage.

Assessing Dependencies Objectively

Another topic was dependency on technology companies outside the European Union. Microsoft as well as IBM and Red Hat can serve as examples here. The point is not to portray individual vendors as inherently unsafe. The relevant question is: what dependency arises when central parts of European or Austrian infrastructure are controlled by companies subject to a non-European jurisdiction?

This view does not only concern cloud and collaboration services such as Microsoft 365 or Azure. Foundational infrastructure components such as enterprise Linux distributions and their subscription, repository, update and management infrastructure can also be part of such a risk assessment.

A real example of the importance of jurisdiction is the case of the International Criminal Court. Microsoft stated in May 2025 that a sanctioned ICC official had been disconnected from Microsoft services as part of sanctions. At the same time, Microsoft made clear that services to the ICC as an organization had not been ceased or suspended.

This example is not a reason for vendor bashing. It does show, however, that European institutions need to include jurisdiction, supply chains and external political or legal dependencies in their risk assessment of critical digital infrastructure, alongside data protection and technical security.

Value Creation in Austria and Europe

Technological sovereignty should not mean replacing large American providers only with large European providers. A resilient European IT landscape needs an ecosystem of vendors, open-source projects, communities, integrators, consulting companies, managed service providers, data centers, research, education and small and medium-sized enterprises.

Specialized small Austrian and European companies in particular can build very deep technical know-how in specific areas. If Europe wants to strengthen technological capabilities in the long term, a market has to exist in which public and strategic digital projects are not implemented exclusively by large corporations.

The question is therefore also where economic value is created through digital transformation: at a few international platforms, or within a European ecosystem that can carry knowledge, operations and further development itself.

European Alternatives as Building Blocks

The conversation also touched on concrete technologies that ForgeOne already works with in practice. XWiki can be a European alternative to Atlassian Confluence in the field of wiki and knowledge management. OpenProject is an open-source project management system with origins and a company in Germany and can replace Jira in certain scenarios. grommunio is developed in Vienna and positions itself as a groupware and collaboration platform as well as a native Exchange alternative.

SUSE is also relevant in this context: as a European enterprise Linux and infrastructure vendor with SLES, SUSE Multi-Linux Manager and Rancher. The multi-Linux approach is especially interesting here. Sovereignty should not be created by simply replacing one vendor lock-in with another. A heterogeneous infrastructure in which different Linux distributions and platforms can be managed together can support choice and the ability to switch.

None of these products is automatically sovereign simply because it comes from Europe or uses open source. Sovereignty emerges from architecture, operations, contracts, jurisdiction, know-how, open standards, supply chains and the ability to actually use alternatives.

Conclusion

For me, digital sovereignty does not mean having to develop everything ourselves. It means having choices and actually being able to use them.

If we want to preserve these choices in Europe over the long term, we need to do more than deploy European technologies. We also need to ensure that knowledge, operations and the associated value creation can emerge in Europe, in large companies as well as in specialized small and medium-sized businesses.

We will keep you updated on further developments around this topic.