Significant changes in the geopolitical landscape are increasingly forcing European businesses to reconsider their technology dependencies. Questions about who controls critical services, which laws apply, and whether access could be disrupted or even halted have become part of the business continuity planning conversation.
Conversations around digital sovereignty have expanded beyond where data is stored and who can access it. They now cover hardware, software, and services, including AI models. Privacy, security, and the prevention of interference are high on the agenda for the public, governments, and businesses.
As Gartner puts it in its report “Europe Context: Magic Quadrant™ for Endpoint Protection,” which includes ESET among its list of Notable Vendors, “Increasing geopolitical tensions and the resulting push for technological sovereignty are leading European cybersecurity leaders to reduce their reliance on foreign cybersecurity providers.”
For businesses, this we feel raises practical questions: Where is our data stored, and who can access it? What happens to the data stored by AI tools? Could we lose access to software we depend on? Will new security risks be introduced? And can we trust our technology providers to ensure business continuity? How are geopolitical decisions affecting my organization?
Key points of this article:
- Digital sovereignty has become a practical business continuity concern, not just a political or regulatory debate.
- Organizations desire more control over where data is stored and processed, who can access it, and whether critical software or services can be disrupted by external actors.
- Availability of sovereign solutions is uneven across the technology market. Alter-natives do exist, and both public and private organizations are implementing them.
- In cybersecurity, Europe already has highly capable providers, in our opinion this includes ESET and others.
A changing world in search of strategic autonomy
In a changing geopolitical landscape, Europe has an opportunity to showcase its existing technological capabilities, including in cybersecurity, and support homegrown alternatives to strengthen its strategic autonomy. Beyond Europe, similar concerns are prompting governments and businesses around the world to reassess their technology dependencies.
Discussions about digital sovereignty raise important questions about jurisdiction, the enforceability of contracts when politics interferes, ownership, data governance, and control over infrastructure. Both public and private organizations are already taking this into consideration: Who can access my data, which legal obligations apply to technology providers, and can business operations continue if access to a critical services change? Sovereignty requirements are already taken into account in some procurement decisions.
The transition is underway. France has adopted Visio, a domestically developed alternative to Zoom and Microsoft Teams; Airbus has selected Scaleway to provide a European cloud environment for the most sensitive business applications; and several German, Danish, and other European governments at the local and national levels are replacing US-based applications with open-source solutions.
ESET signed a framework agreement as the first cybersecurity vendor to meet the Dutch government’s push for greater digital sovereignty. This allows public sector companies to access solutions under pre-agreed terms covering privacy, data processing, data location, and oversight through ESET PRIVATE solutions.
Recent policy decisions also show how sovereignty can impact business continuity. In June 2026, US export restrictions on access by foreign nationals prompted Anthropic to suspend its Fable 5 and Mythos 5 models. It has also been reported that Microsoft canceled services to the International Criminal Court’s chief prosecutor following the decision to open an investigation into actions by Israeli officials in Gaza, to comply with US sanctions. These examples illustrate how a government decision can abruptly affect the availability of technology that organizations depend on.
Alongside service availability, organizations must also consider the legal obligations governing access to their data. Under the US CLOUD Act, covered providers subject to US jurisdiction can be required to disclose customer data in response to valid US legal processes, including law enforcement requests, even when that data is stored outside the US. And in August 2026, a US memorandum allowing private firms to conduct cyber surveillance operations follows a similar track. The concerns also apply to other jurisdictions, particularly Chinese technology providers and their legal obligations to support Chinese Intelligence goals.
As a result, digital sovereignty is increasingly seen as a way to reduce political risk, ensure business continuity, and maintain control over sensitive data. Organizations must assess where data can be accessed, which legal obligations apply, and where it is stored. However, sovereignty is not always the best solution, as control, trust, and autonomy, rather than geography, matter most.
A journey toward autonomy
Progress toward greater autonomy will vary as contracts come up for renewal, and replacing deeply embedded platforms takes time, investment, and planning. But these challenges should inform the transition rather than prevent it.
Greater interoperability, a broader choice of trusted suppliers, and measures to reduce vendor lock-in can help organizations build resilience while retaining access to international innovation. For AI, this assessment also includes who owns and governs the models, where they are hosted, how they are trained, and whether security and data privacy are ensured.
As a “Made in EU” company since its creation over 35 years ago, ESET offers a trusted alternative to European and non-European customers, helping organizations build independent capabilities and mitigate risk exposure.
Ultimately, greater strategic autonomy should enable organizations to make decisions about their security and risk exposure independently, autonomously, and securely.
Conclusion
The pursuit of strategic autonomy should give organizations greater control over their data, technology, and operations. In practice, this means strengthening strategic autonomy and maintaining business continuity amid geopolitical uncertainty. Trust is central to that effort. It rests on proven security, clear accountability, and providers that organizations can rely on as circumstances change.
Frequently asked questions (FAQs)
How do digital sovereignty and digital independence differ?
On the one hand digital sovereignty focuses on jurisdiction, governance, and control. For some, it is a technical requirement; for others, it’s a business decision. On the other hand, digital independence focuses on the ability to make autonomous decisions to maintain operational resilience. This includes diversifying suppliers, reducing vendor lock-in, and selecting solutions according to specific risks. Both digital sovereignty and independence are steps toward strengthening strategic autonomy.
Why is digital sovereignty becoming more important for European businesses?
Geopolitical decisions can affect access to critical technologies, the availability of services, and control over sensitive data. Organizations therefore need to assess their providers’ legal exposure and supply chain dependencies alongside technical security. These considerations increasingly matter for business continuity and trust.
Does digital sovereignty mean cutting off all foreign technology providers?
Yes, depending on the context. For example, French sovereignty requires a full French technology stack, while EU sovereignty allows for a mix of EU technologies. Claims of sovereignty must be supported by the legal, technical, and operational controls required in each case.
What should organizations consider when assessing digital sovereignty?
Organizations should look at data residency, access rights, encryption key control, cloud dependency, software control, supply chain transparency, AI data exposure, local support, operational resilience, and exit strategies.
Why is cybersecurity a good starting point for digital sovereignty?
Endpoint protection and cybersecurity services handle sensitive telemetry, threat data, operational decisions, and incident response. Choosing reliable providers with local data handling, regional support, transparent governance, and localized threat research can strengthen resilience and trust.
Gartner, Inc. Magic Quadrant for Endpoint Protection. Deepak Mishra, Evgeny Mirolyubov, et al. 26 May 2026.
Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.








