Summary
Philipp Holzmann’s core message was that digital sovereignty in cloud computing must be translated from political concern into concrete, auditable technical criteria. Speaking from the German Federal Office for Information Security, he framed the issue through Europe’s dependence on non-European digital infrastructure: only 20% of infrastructure and technologies come from the EU, while more than 70% of widely used AI base models come from the US. He stressed that dependencies are not inherently bad and that sovereignty does not mean autarky, but recent geopolitical and regulatory events show why governments and companies need a clearer view of which cloud services they can use autonomously, securely, and under conditions they understand.
Key Topics
5 key topics from Philipp Holzmann at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Assess cloud dependencies before geopolitical decisions expose operational risk.
- Use C3A criteria to define required sovereignty levels for workloads.
- Demand transparency on software, hardware, data locations, and service dependencies.
- Test disconnect and reconnect capabilities for non-EU service links.
- Map sovereignty requirements against existing C5 and EUCS security controls.
“the availability of critical cloud infrastructure or, in this case, AI services can vanish overnight”

Philipp Holzmann
Up Next

Next in agenda
From awareness to action: SME Cyber Security
Emiel Kerpershoek
SAlso on digital sovereignty
Sovereignty: From Promise to Practice


Also on digital sovereignty
