Your data is in Europe. Your knowledge is in a chat.
Data sovereignty is the old question: where is the data? The new one hardly anyone asks: can we get to our knowledge if the AI provider shuts down, blocks us or doubles the price? Why technical sovereignty is a leadership decision, with a sovereignty check for your next leadership meeting.
In short: The sovereignty debate has circled one question for years: where is our data? That one is mostly answered by now. The question hardly anyone asks is: where is our knowledge? One to two years of thinking sit in chats that can be neither exported nor moved. Sovereignty does not mean running everything yourself. It means being able to leave at any time. Whether your company can is not an IT question. It is a decision by the leadership team about a dependency it mostly never took on consciously.
Data sovereignty you have settled. Technical sovereignty nobody has asked about yet.
An owner I have known for years said something in a conversation that has stayed with me since. It is not revenue that keeps him up at night, he said. It is the thought that a whole year of his team’s thinking sits in a chat he can neither download nor take with him. “If they switch that off tomorrow, all of it is gone.”
The question did not come out of an IT meeting. It came out of a sparring session about his business model. It is the new version of an old question, and that is exactly why it gets missed.
01 · The question you settled long ago
When managing directors talk about AI and control, they almost always mean data sovereignty. Where is the data, who has access, under which legal system? That is legitimate, and in Germany it is the dominant concern: in a Bitkom survey published in March 2026, 77 percent of companies name data protection requirements as a barrier to digitalisation, more often than any other item. At the same time, only 41 percent use AI.
That question is solvable, and most have solved it. EU hosting, a data processing agreement, data classes, no customer names in public models. That was a decision, and you made it, even if in daily life it ran as a data protection check and was never called one.
Only that was the question about location. The question about your knowledge is this: where is it, and can you take it with you? Yes. If you decide it before it matters.
02 · The question nobody has settled yet
What has happened over the past one to two years has little to do with data storage. Leaders and teams have started working with language models: drafting proposals, thinking through strategies, preparing customer conversations, testing decisions. The model gets to know the company along the way. The chats become the memory. The knowledge sits less in the file than in the history: in the discarded versions, the reasoning, the language a company uses about itself.
And that history is less yours than you think. I tried it myself. After my switch from OpenAI to another provider I wanted to take my chat histories with me. The button is there, two clicks under data controls, the file arrives by email. Mine never did. Over months, started again and again, the same error message every time, most recently yesterday. It may well be user error. For the question of whether I can take my work with me, it makes no difference. On a company plan the button is not there at all any more, not even via the administrator. Move from a personal account into a company workspace and you lose it. With five users that is annoying. With fifty it is a switching barrier that no one ever decided on.
The first dependency, though, is not even the provider. It is the account. The history belongs to the person who runs it. If your head of sales leaves, his year of AI-supported customer work leaves with him, and nobody notices, because none of it was ever in the CRM. That is the same key-person risk you already keep an eye on when it comes to responsibilities, only in a place nobody has looked so far.
Your data may be in Europe. Your knowledge is in a chat.
That is the difference between data sovereignty and technical sovereignty. The first asks about the location. The second asks about the way back.
| Data sovereignty | Technical sovereignty | |
|---|---|---|
| The question | Where is our data, who has access? | Can we switch without losing knowledge? |
| The usual answer | EU hosting, DPA, data classes | ”We have not talked about that yet.” |
| Who answers it | IT and data protection officers | The leadership team |
03 · The worst case had a date
Three things can happen to a company that has entrusted its work to an AI provider. All three happened in 2026.
First: the provider is gone. In June 2026 Anthropic had to switch off its two strongest models on an order from the US Department of Commerce, with no notice. The order applied to all foreign nationals, regardless of where they were sitting. Because nationality cannot be verified at the interface, the provider switched the models off for everyone, including its own people. Anyone who had built a work process on them came to a stop. What caused it was not a technical outage but a political decision in another country.
Second: the price changes. Providers of language models adjust plans, quotas and billing models at short intervals. If you cannot switch, you go along with every one of those adjustments, for years, with no negotiating position.
Third: the terms change. The export that works today may not work tomorrow. The EU Data Act, in force since September 2025, obliges cloud providers to enable switching and removes switching charges entirely from January 2027. That is progress for storage and infrastructure. Whether your chat histories, prompts and workflows actually become portable, though, is decided in your contract and in the way you work, and in no law.
Dependency does not come from choosing a provider. It comes from the absence of a way back.
04 · If you don’t decide, your provider will
In your company, a decision of considerable weight is in force that nobody made and nobody is responsible for. It gets made anyway, every day, by your provider: on price, terms and availability. Here comes the objection I hear most often: “That is what we have IT for.” IT can answer the question. In my view it should not decide it.
Try the procurement test. For suppliers you have rules: no single source for a critical part, no dependency above 30 or 40 percent, no contract without an exit. For the provider that by now carries proposals, strategy work and customer knowledge, none of them applies. Your procurement team would never have signed this contract. It was signed by credit card, in five minutes, by someone who only wanted to try out a tool. A managing director takes on dependencies like that consciously or not at all. With AI, most have taken them on without noticing. Fail to lead AI and you do not only get Shadow AI, you get shadow dependencies too.
On top of that comes a bottleneck that appears in no cost calculation. The same owner said: in his company there is exactly one person who could handle a switch like that technically, and that person is booked out for three years. In a mid-sized company of 150 people it is no different, except that the one person there has no time even today. A way back that no one can walk is not a way back.
Sovereignty does not mean running everything yourself. Sovereignty means being able to leave at any time. That disappoints both camps. The “everything in our own cloud” camp sometimes confuses control with effort. Set up properly, with a current backup and on open standards, your own virtual server at a hosting partner can make exactly that difference: switching stays possible at low cost. The “EU hosting is enough” camp confuses a contract clause with a strategy. The question is never whether you are dependent. You are: on Microsoft, on your bank, on your largest customer. The question is which dependencies you know about, consciously accept and can resolve when it counts. Where your leadership team stands on that question shows in its AI maturity faster than in any tool list.
05 · Thirty minutes to take the decision back
Thirty minutes in your next leadership meeting, no IT, no vendors. Five questions, each answered individually before anything is discussed:
- Which work today sits exclusively in AI chats? Not which tools, but which work: proposals, strategy, customer preparation. Hopefully no personnel decisions.
- Can we export it, and has anyone tried? The answer “in theory, yes” counts as a no.
- What happens on the day the provider is unreachable? Three days. Not three hours.
- Who would have the time and the skill to carry out a switch? A name, not a department.
- Which of these dependencies do we as leadership consciously accept? That is the actual decision. The four questions before it are preparation.
Watch the pauses more closely than the answers. Where a question produces silence, that is where the dependency sits that no one ever decided on.
The line to remember
Your data may be in Europe. Your knowledge is in a chat.
Next step
If the five questions produced more silence than answers, that is no reason to start comparing providers now. It is the moment when leadership decides what AI is meant to serve in the company at all, and which dependency is bearable for that. That is exactly what the AI Compass clarifies, before a tool gets chosen. If you would rather work the question through with other managing directors, you will find it again in the Growth Circle on AI in leadership.
At JUSTGROW we have made this decision: we run our own AI platform on an open-source basis at a hosting partner of our choosing, with none of the large US providers in between. We built it together with millionsteps, where I am involved behind the scenes. That is a dependency too. But one with the way back built in.
Sources: Bitkom, Digitalisation of the economy 2026, press release of 11 March 2026 (604 companies with 20 or more employees), in German. OpenAI Help Center, Managing data, sharing, and privacy in ChatGPT Business, as of September 2026. The export attempt described is my own experience with a personal account. European Commission, Data Act explained. On the shutdown in June 2026: eurotopics press review and Kanzlei Ferner on the US export controls, in German. The conversation with the owner (strategy consultancy, fewer than ten staff) is reproduced anonymised. The distinction “location versus way back” and the sovereignty check: JUSTGROW.
Frequently asked questions
What is the difference between data sovereignty and technical sovereignty in AI?
Data sovereignty answers where your data sits, who has access to it and under which legal system. Technical sovereignty answers whether you can switch providers without losing knowledge, working methods and results. The first question is usually settled with EU hosting and a data processing agreement. The second one is asked by very few companies, even though it is where the larger risk now sits.
Is an EU server location enough for AI sovereignty?
No. An EU server location settles the legal system and the storage location of your data. It says nothing about whether you can export chat histories, prompts, workflows and results and keep using them at another provider. Sovereignty is the ability to switch, not the address of the data centre.
What are the risks when company knowledge sits only in AI chats?
Three: the provider shuts down or gets blocked, as happened in June 2026 when Anthropic had to switch off its two strongest models on an order from the US Department of Commerce, with no notice. The provider raises the price and you cannot switch, because one to two years of thinking sit in the chat. Or the export that exists in theory does not work when it counts: at OpenAI the button is there in a personal account, no longer on a company plan, and even in a personal account the exported file is no substitute for the working environment.
Why is AI sovereignty a job for the leadership team and not for IT?
Because IT can answer the question technically, but should not decide which dependency the company takes on. Whether customer knowledge, strategy work or pricing logic may sit with a provider from which there is no way back is a risk decision for leadership. The same as with suppliers or key accounts.
How does a leadership team check its AI dependency in concrete terms?
With five questions in thirty minutes: which work today sits exclusively in AI chats? Can we export it, and has anyone tried? What happens on the day the provider is unreachable? Who has the time and the skill to carry out a switch? And which of these dependencies do we as leadership consciously accept? The last question is the leadership decision, the four before it are preparation.