Digital Sovereignty_Cover

For a long time, digital sovereignty remained confined to the realm of theoretical debate: an ethical imperative lacking, however, an immediate operational framework. The advent of LLMs has upended this paradigm, transforming technological autonomy from an abstract concept into a pillar of corporate strategy.

Generative AI has made Europe’s technological dependency visible, measurable, and above all urgent. It is no longer simply a matter of knowing where corporate data resides or who manages the datacenters: today it means understanding who controls the models with which our companies reason, decide, and produce.

2025 and 2026 have accelerated this awakening on multiple fronts simultaneously. In November 2025, all 27 EU member states signed the Declaration for European Digital Sovereignty, an unprecedented political act that explicitly recognises technological dependency as a strategic risk.

During the same period, three regulations came into force that directly affect companies’ technology chains: the AI Act, with the first obligations for GPAI systems operational from August 2025; NIS2, which since 2024 has extended cybersecurity responsibility to 18 critical sectors (including supply); and DORA, which since January 2025 has imposed stringent requirements on financial sector resilience regarding third-party ICT providers.

The paradigm has shifted: the question is now the infrastructural origin of AI, not merely its use. For data-driven companies, the key question is who actually owns the technology embedded in their core stacks.

The Generative AI knot: a structural dependency

When we talk about Generative AI in business, the landscape is dominated by a small number of players: OpenAI’s GPT, Google’s Gemini, Anthropic’s Claude, Meta’s Llama models. All subject to United States jurisdiction: a geopolitical fact with concrete legal implications.

The CLOUD Act of 2018 requires US companies to provide American authorities with access to data they manage, regardless of where that data is physically stored. A European company that sends data to an American API to generate text or classify a document is transmitting that data to infrastructure subject to this regulation. It does not matter if the datacenter is in Europe: if the provider is American, the CLOUD Act applies.

The “sovereign” solutions offered by European hyperscalers mitigate the problem but do not solve it. They reduce the risks of physical access, but do not eliminate American jurisdiction over the parent company. As the European Data Protection Board has clarified, data transfer mechanisms to the US remain structurally fragile until this legal asymmetry is addressed at the root.

For Generative AI the problem is amplified: unlike storage, data does not simply “reside” in one place, but is processed by models trained on proprietary corpora, with non-inspectable architectures, by companies that are not answerable to European law.

Companies integrating these models into their operational workflows are essentially outsourcing part of their cognitive process to non-EU entities.

The European gap: what is really missing

Europe is not absent from the AI landscape, but it is honest to acknowledge where the structural limitations lie.

On the models front, the most significant case is Mistral AI: a French startup with quality open-source models. A symbol of Europe’s capacity to compete on innovation. Yet even Mistral distributes its models through Azure and AWS, a paradox that stems from the market: without a sufficiently large and organised European enterprise customer base, even the best European players must rely on American infrastructure to scale.

On the compute front, the dependency runs even deeper. The chips required to train and run inference on large models (NVIDIA GPUs) are designed in the United States and manufactured by TSMC in Taiwan. Europe currently has no autonomous production capacity for this type of semiconductor. The European Chips Act targets 20% of global production by 2030, but we are still far from that threshold, and training frontier models requires clusters of thousands of chips today, not in years’ time.

On the HPC infrastructure front, Europe has invested significantly: CINECA’s Leonardo supercomputer in Bologna ranks among the ten most powerful in the world; LUMI in Finland, Jupiter in Germany, and MareNostrum 5 in Barcelona complete a high-performance European ecosystem. The EuroHPC programme has distributed computing resources for research and industrial projects. But access to these systems remains predominantly academic, and the gap with the inference capabilities of major American cloud providers, available via API in seconds, remains enormous in terms of operational accessibility.

The result is a hybrid situation: Europe has expertise, talent, and political will, but does not yet have a complete and accessible supply chain for companies wishing to use AI in production without depending on American providers.

The viable response: not substitution, but decoupling

It would be counterproductive to suggest that European companies stop using American models. GPT and its equivalents are powerful tools, available today, with mature ecosystems. The problem is not using them: it is depending exclusively on them, without the ability to switch, control, or move one’s workflows elsewhere.

The most effective strategy is therefore not substitution, but decoupling. 

An architecture that decouples business applications from specific models introduces an intermediate layer, often called an AI Gateway or Proxy Layer, that manages the routing of requests to different providers, applies data governance policies to data in transit, monitors costs, and ensures system observability. 

The benefits of this approach are tangible:

  • Multi-provider flexibility: if today a company uses GPT for document summarisation and Mistral for internal classification, tomorrow it can add an on-premise open-source model without rewriting application code. The gateway abstracts the model from the application.
  • Data governance: a well-configured gateway can automatically detect and mask sensitive information, such as personal data, account numbers, and confidential details, before it leaves the corporate perimeter. This does not resolve the legal issue of the CLOUD Act, but it drastically reduces the risk surface.
  • Cost control: the ungoverned proliferation of LLMs within a company, a phenomenon known as AI Sprawl (for a deeper dive, read our dedicated blog post), leads to expenditure that is difficult to track and optimize. A centralized gateway allows budgets to be assigned by team, project, or use case, and enables semantic caching mechanisms that reduce redundant API calls.
  • Observability and quality: knowing how models are used, with what prompts, and with what outcomes, is essential for ensuring quality and identifying anomalous usage, including Shadow AI (read more here), meaning the unauthorized use of LLMs by employees with sensitive corporate data.

This approach is compatible with the requirements of NIS2 (traceability and supply chain risk management), DORA (resilience of third-party ICT providers), and the AI Act (logging and monitoring obligations for high-risk systems).

Radicalbit AI Gateway: a concrete approach to decoupling

Radicalbit AI Gateway is designed precisely for this type of architecture: an orchestration layer that sits between business applications and AI models, regardless of provider. 

The product is built around three pillars:

  • Governance and Security: the AI Gateway includes automatic PII data detection and masking functionality prior to sending data to the model. It integrates LLM-as-judge mechanisms for automated response quality evaluation, and enables granular policies defining which data can be sent to which providers. For companies subject to NIS2, DORA, or the AI Act, this level of control has become an operational requirement, not an option.
  • Cost Control: through intelligent routing and semantic caching, the Gateway optimizes model usage. Similar requests are served from cache, reducing API calls. Budgets can be allocated by team or project, with configurable alerts.
  • Observability: complete logging of every interaction, aggregate usage metrics by model and team, real-time dashboards. Observability is the prerequisite for any optimisation strategy: you cannot govern what you cannot see.

On the technical side, Radicalbit AI Gateway exposes an interface compatible with the OpenAI APIs, meaning that applications already integrated with GPT require no code changes to pass through the orchestration layer. Routing to different providers (OpenAI, Anthropic, Mistral, Llama locally, or any compatible endpoint) is configured via YAML files, with no application-level changes required.

This design directly addresses thevendor lock-in issue: the application does not know and does not need to know which model it is using. The choice of model becomes a governance decision, not an architectural constraint. 

For more information about our solution, visit the dedicated Radicalbit AI Gateway page.

Digital Sovereignty is built one layer at a time

Digital sovereignty in the AI era is not a goal reached through a single decision: migrating everything on-premise, abandoning American hyperscalers, waiting for Europe to produce its own frontier models. None of these scenarios is realistic in the short term. 

Sovereignty is built by progressively reducing unnecessary dependency points and increasing the capacity for control, observability, and portability.

On the regulatory side, Europe is doing its part: the AI Act defines precise obligations; NIS2 and DORA extend accountability along the technology supply chain; the Declaration for European Digital Sovereignty signals a political will that did not exist five years ago.

On the industrial side, every company that adopts a multi-provider architecture, implements centralized LLM governance, and chooses European solutions where available and competitive, contributes to building the aggregate demand that makes the development of alternatives possible.

The orchestration layer is not the complete solution to the problem of digital sovereignty. But it is one of the few concrete tools available today that allows companies to begin this journey without waiting for the European ecosystem to reach the maturity of American hyperscalers. 

Taking back control means knowing where your data is, who processes it, and having the ability to change course if conditions change.


Discover how Radicalbit AI Gateway works and book a demo to see how to decouple your applications from providers, govern data in transit, and build a sovereign, resilient AI architecture.

©2026 Radicalbit is owned and operated by Fortitude Group Srl
All rights reserved VAT IT04268680263