
Sovereignty is not a checkbox. It’s control, with an acceptable-risk sidecar.
The wrong instrument
Most procurement teams have been handed a binary tool for a non-binary problem.
The vendor questionnaire asks: Is your data stored in-region? The vendor answers yes. The box gets ticked. The contract gets signed. And eighteen months later somebody in legal discovers that “in-region” was a statement about geography, not about jurisdiction — and that the two were never the same thing.
Pass/fail is not a sovereignty assessment. It’s a liability transfer. It moves the risk from the vendor to you, and it does it without anyone writing down what the risk was.
The alternative is not to reject everything. Nobody builds a resilient enterprise by refusing to buy. The alternative is a different verdict structure:
- Accept — inside our sovereignty boundary, no conditions.
- Accept with compensating control — outside the boundary, but the exposure is bounded, named, and owned.
- Reject — the exposure touches the crown jewels and cannot be bounded.
Three verdicts, not two. And every one of them is written down, signed by a named human, and given an expiry date.
Seven questions that change the answer
Each of these has cost a real organization real money. None of them appears on a standard security questionnaire.
1. Does my vendor depend on a frontier model to deliver the work?
The exposure is two-sided, and most buyers only see one side.
The pricing side is obvious: your vendor’s cost basis is somebody else’s per-token meter. When that meter moves, your invoice moves — or your vendor’s margin evaporates and their service quality moves instead. You did not negotiate with the model provider. You have no seat at that table and no notice period.
The availability side is the one that bites.
In June 2026, Anthropic released Claude Fable 5. Three days later, the US government applied export controls to the model, requiring access to be restricted for foreign nationals inside and outside the United States. Because the directive took effect immediately and nationality could not be verified in real time, Anthropic suspended access for every user. The models were unavailable for nineteen days before the controls were lifted at the end of the month. [1] [2] [3]
Read that again as a procurement officer in Tel Aviv, Munich, or São Paulo. The model your vendor’s product runs on went dark — globally — because of a foreign export-control action against a class of user you happen to belong to. Not a price change. Not a deprecation notice. An immediate, mid-contract, zero-notice removal of the thing your agent workflow was built on.
Ask: Which specific models are in the request path? Whose account are they billed through? What is your documented failover, and have you tested it? What contractual notice do we get on model change, price change, or availability loss?
Acceptable looks like: a vendor who can name the model, name the fallback, and show you the eval results proving the fallback holds quality. Unacceptable looks like: “we use best-in-class models.”
2. Is my vendor subject to a law outside my jurisdiction?
Residency answers a geography question. Jurisdiction answers a legal one. Only the second is enforceable against you.
In June 2025, Microsoft France’s director of public and legal affairs testified under oath before a French Senate inquiry into public procurement and digital sovereignty. Asked whether he could guarantee French citizens’ data would never be passed to US authorities without French authorization, his answer was: “No, I cannot guarantee it.” Under the CLOUD Act, US companies can be compelled to produce data regardless of where it is stored. The statute attaches to the company, not the postcode. [4] [5] [6]
This was not a leak. It was sworn testimony from the largest cloud vendor on earth, and it confirmed what the statute always said. Every European buyer holding a “sovereign cloud” contract with a US-owned entity had their answer that day.
Now extend it one layer. Your vendor is a German AI consultancy. Sovereign, local, in-region. Their orchestration layer runs on a US hyperscaler. Their model provider is American. Their observability tooling is a US SaaS product. Which of those four companies is outside your jurisdiction? All of them. Your vendor is European. Your supply chain is not.
Ask: Where is the vendor incorporated, and who is the ultimate parent? Which of your subprocessors are subject to extraterritorial disclosure law? Will you notify us of a compelled-disclosure order, and what are you legally permitted to tell us?
Acceptable looks like: the exposure exists, it’s mapped, and the data classes that touch it are ones you’re willing to see disclosed.
3. What happens when the vendor is acquired?
Every sovereignty assessment you run has an unstated assumption: that the company you assessed will still be that company at renewal.
Broadcom closed its VMware acquisition in late 2023. What followed is now the standard cautionary tale in European IT. CISPE — the European cloud infrastructure trade body, and an interested party — describes drastic price increases, product bundling, prepayment obligations, and minimum purchase commitments based on potential rather than actual usage, cumulatively exceeding 1,000%. Individual customer accounts reported in the trade press describe renewals measured in multiples rather than percentages. In January 2026, Broadcom terminated most of its European cloud service provider partner program, cutting all but a hand-picked group — which for many providers eliminated a substantial share of revenue outright. CISPE filed a competition complaint with the European Commission in March 2026 and requested interim measures; Broadcom said it strongly disagreed with the allegations and was investing in European partners. [7] [8] [9] [10]
Set aside who is right, and discount the headline percentages the way you would discount any advocacy number. The procurement lesson is structural, and it survives the dispute: the customers who got hurt worst were the ones with no exit. The technology hadn’t changed. The ownership had. And the switching cost they’d never measured turned out to be the entire negotiating position.
A change of control can move a vendor’s jurisdiction, its pricing model, its partner ecosystem, and its product roadmap in a single announcement. Your five-pillar assessment was accurate on the day you ran it, and worthless the day after the deal closed.
Ask: Who owns you? Who has board control? Is there a change-of-control clause that lets us exit without penalty? What happens to our data, our keys, and our license terms if you’re acquired by an entity outside our jurisdiction?
Acceptable looks like: a priced, tested exit. Not a clause — a rehearsal.
4. Who is in the chain behind the vendor you actually contracted with?
Your fourth parties will breach you, and you will have no privity with them.
In mid-2023, the Clop ransomware group exploited a zero-day in MOVEit Transfer, a managed file transfer product from Progress Software. Among the affected users was Zellis, a UK payroll provider. Through that single upstream compromise, employee data from British Airways, the BBC, Boots, Aer Lingus and Ireland’s HSE was exposed — organizations that had never bought anything from Progress Software and in most cases had never heard of it. [11] [12] [13]
The sovereignty version of this is worse, because AI systems have more subprocessors than traditional software and they’re less visible. Your vendor’s agent stack may touch a vector database, an embedding provider, an inference host, a guardrail service, a logging pipeline, and an eval platform. Each is a separate company in a separate jurisdiction with a separate breach surface. Your DPA names three of them.
Ask: Give us the complete subprocessor list, including inference and observability. What’s the notification period for adding one? Do we have a right of objection, and what happens if we exercise it?
Acceptable looks like: a list that’s longer than you expected, kept current, with a real objection mechanism. Unacceptable looks like a short list.
5. Who can turn it off?
This is the one nobody wants to ask, and it’s the one that ended the debate in Europe.
In 2025, the email account of the International Criminal Court’s chief prosecutor was suspended following a US executive order sanctioning him, and he moved to a Swiss provider. Microsoft’s president disputed the framing, saying the company never ceased or suspended services to the ICC. Later reporting indicated a more complicated sequence, in which the court itself ended the prosecutor’s access under pressure. The ICC subsequently adopted OpenDesk, an open-source collaboration suite from the German Centre for Digital Sovereignty. In the Netherlands, the incident triggered urgent government reassessment of digital exposure. [14] [15] [16] [17]
Here’s why the dispute over what happened is more instructive than a clean answer would have been: nobody’s contract said what was supposed to happen. An organization built its operations on a platform, a geopolitical event occurred, and there was no clause, no runbook, and no agreed account of who had the authority to do what. That ambiguity is the risk. You do not want to discover the boundaries of your vendor’s discretion by living through them.
Ask: Under what circumstances can you suspend our service? Who authorizes it? What notice do we get? If you are compelled to act against us by your home government, what is your process, and can you tell us?
Acceptable looks like: an honest answer, in writing, from someone with authority. The answer “that would never happen” is not an answer.
6. Where does the exhaust go?
Agentic systems leak differently than applications do.
Traditional software risk assessment focuses on the data store. Agentic systems generate a second data estate that most procurement processes ignore entirely: prompts, traces, tool-call logs, retrieved context, memory, eval sets, and fine-tuning corpora. That exhaust is often the most sensitive material in the system — it contains your business logic, your customer specifics, and your decision criteria in plaintext — and it routinely flows to a completely different set of vendors than your production data does.
The pattern is consistent and boring: production data sits in a carefully chosen in-region store; the observability stack that traces every agent step is a US SaaS product wired in during week two of the build by an engineer who was solving a debugging problem, not a jurisdiction problem.
Ask: Where are prompts, traces, and tool-call logs stored, and for how long? Is any of it used for model training or product improvement — by you or by your subprocessors? Can we run the observability layer inside our own boundary?
Acceptable looks like: exhaust treated as production data, with the same residency and retention rules.
7. Can you actually leave?
Financial sovereignty isn’t about price. It’s about whether the price is negotiable.
The question is not “what does it cost.” It’s “what would it cost to stop.” If the honest answer is eighteen months and a rebuild, you don’t have a supplier — you have a dependency, and every renewal conversation from now on is a monologue.
For agentic systems specifically, exit means more than a data dump. Agent definitions, tool schemas, prompt libraries, memory structures, and evaluation suites are the accumulated institutional knowledge of your deployment. If they live only in the vendor’s proprietary format, you can take your data and still leave the valuable part behind.
Ask: What’s the export format for agent definitions, prompts, memory, and eval sets? Have you done a customer migration off your platform — can we speak to them? What’s the documented time-to-exit?
Acceptable looks like: a number you’ve tested. Not a clause you’ve drafted.
Risk is fine. Surprise is not.
Here is the part procurement teams need permission to hear:
You are allowed to accept risk.
You are allowed to buy the American vendor. You are allowed to run on a hosted frontier model. You are allowed to take a dependency on a company that could be acquired next quarter. Every one of those can be the right commercial decision, and the organizations that refuse all risk in the name of sovereignty end up with a compliant architecture that does nothing useful.
What you are not allowed to do is be surprised.
Look at the pattern across every one of these stories. In each case, the exposure was documented in public before it detonated:
- The CLOUD Act was enacted in 2018. Its extraterritorial reach was discussed for seven years before a Microsoft executive confirmed it under oath in a French Senate chamber. Nothing about the legal position changed that day — only the number of buyers who could no longer claim they didn’t know.
- Broadcom’s leadership publicly committed to a dramatic increase in VMware’s standalone EBITDA within three years of closing. European industry groups argued that such a jump could only come from monetizing a locked-in customer base. The arithmetic was on the record before the renewals arrived. [10]
- France’s SREN law, adopted in 2024, requires sensitive data to sit on infrastructure with sovereignty guarantees — which is why the Health Data Hub, hosted on a US-owned platform, ended up needing a tender to move. [18] That contract was defensible when signed and indefensible three years later, because the policy moved and nobody had modeled the possibility that it would.
None of these organizations was destroyed by taking a risk. They were embarrassed by not having named it. There’s a real difference between a CIO who says “we accepted CLOUD Act exposure for our CRM data in 2024, here’s the memo, here’s who signed it, here’s the trigger that would make us revisit” and one who says “we were told the data was in Frankfurt.”
The first is a professional managing a portfolio. The second is an ostrich — and the ostrich posture is the only genuinely unacceptable position in this entire discipline.
The mechanic: from questionnaire to risk register
Map every finding to the pillar it actually threatens, then decide per pillar rather than per vendor.
| Pillar | The litmus test | What a vendor answer must survive |
|---|---|---|
| Territorial | Where do data and compute physically reside — at rest and in motion? | Inference endpoints, not just storage buckets |
| Operational | Who runs and secures the environment? Who holds keys, pagers, audit logs? | Follow-the-sun support access from third countries |
| Technological | Who owns the stack and the IP? Can you audit, fork, self-host? | Proprietary formats with no export path |
| Legal | Which jurisdiction governs access? | Ultimate parent, subprocessors, compelled disclosure |
| Financial | Are you free from lock-in? Is cost predictable and exit priced? | Upstream per-token exposure, change-of-control |
Then produce the only artifact that matters — a Risk Acceptance Record, one page per accepted exposure:
- What the exposure is, in one sentence a board member understands.
- Which pillar it lives under.
- Why we’re accepting it — the commercial benefit, stated plainly.
- What bounds it — the data classes excluded, the compensating controls in place.
- Who owns it — a named executive, not a department.
- When it expires — a date, not “ongoing.”
- What triggers a re-review — acquisition, model change, regulatory shift, price move beyond X%.
Seven fields. If a vendor relationship can’t produce that page, the problem isn’t the vendor. It’s that you don’t yet know what you bought.
The close
There are hundreds of vendor questions that bear on sovereignty, and no organization has the time to ask all of them. The goal was never to restrict everything. Restriction isn’t sovereignty — it’s just a slower form of dependency, on the few vendors permissive enough to clear your checklist.
The goal is consistency and ownership. A decision that matches your stated policy, taken by someone with the authority to take it, written down where an auditor, a regulator, or a successor can find it.
Self-awareness is the whole battle. Know where the gaps are. Know which ones you’ve decided to live with. Own them out loud.
You will not be judged on the risk you took. You’ll be judged on whether you knew you were taking it.
Action item
Procurement officers should replace binary pass/fail procurement questionnaires with a three-verdict framework—Accept, Accept with Compensating Control, or Reject—and mandate a signed, single-page Risk Acceptance Record (RAR) before executing any AI or cloud contract. Shift focus from basic geographic data residency to auditing deep operational and legal dependencies, including sub-processor chains, foreign jurisdictional reach under laws like the CLOUD Act, and tested exit paths for proprietary agent logic. Ensure every accepted risk is explicitly bounded, assigned to a named executive owner, and tied to clear expiration dates and re-review triggers—such as vendor acquisitions, model deprecations, or price shifts—to eliminate unmonitored supply chain exposure.
Sources
Frontier model dependency — Fable 5 / Mythos 5 export controls (June 2026)
- Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5,” 12 June 2026 — https://www.anthropic.com/news/fable-mythos-access
- Anthropic, “Redeploying Claude Fable 5,” 30 June 2026 — https://www.anthropic.com/news/redeploying-fable-5
- CNBC, “Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5,” 30 June 2026 — https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
- Background on the trigger and the standoff: Forbes, 16 June 2026 — https://www.forbes.com/sites/anishasircar/2026/06/16/anthropic-disabled-fable-5-and-mythos-5-after-a-us-export-control-order-heres-what-happened/
Extraterritorial jurisdiction — CLOUD Act and the French Senate testimony (June 2025)
- The Register, “Microsoft admits it ‘cannot guarantee’ data sovereignty,” 25 July 2025 — https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/
- Forbes, “Microsoft Can’t Keep EU Data Safe From US Authorities,” 22 July 2025 — https://www.forbes.com/sites/emmawoollacott/2025/07/22/microsoft-cant-keep-eu-data-safe-from-us-authorities/
- SDxCentral, “Microsoft tells French lawmakers it can’t protect user data from US demands,” 21 July 2025 — https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/
- Primary source: Sénat (France), commission d’enquête sur la commande publique — audition of Microsoft France (Anton Carniaux, Pierre Lagarde). Cite the compte rendu directly if you can pull it.
- Statutory basis: CLOUD Act, Division V, Consolidated Appropriations Act 2018; 18 U.S.C. § 2713.
Change of control — Broadcom / VMware
- CISPE, “CISPE Files Competition Complaint Against Broadcom, Urges Immediate EU Action,” 19 March 2026 — https://www.cispe.cloud/cispe-files-competition-complaint-against-broadcom
- Network World, “VMware customers in Europe face up to 1,500% price increases under Broadcom ownership” — https://www.networkworld.com/article/3994107/vmware-customers-in-europe-face-up-to-1500-price-increases-under-broadcom-ownership.html
- Network World, “Broadcom refuses to backtrack on huge VMware price increases, claims European cloud watchdog,” 30 October 2025 — https://www.networkworld.com/article/4081344/broadcom-refuses-to-backtrack-on-huge-vmware-price-increases-claims-european-cloud-watchdog.html
- The Daily Perspective, “Broadcom faces new EU antitrust complaint over VMware closure,” 19 March 2026 — https://thedailyperspective.org/article/2026-03-19-broadcom-in-the-european-dock-over-vmware-partner-purge-84403816
Fourth-party supply chain — MOVEit / Zellis (2023)
- The Register, “British Airways, BBC hit in MOVEit supply-chain attack,” 5 June 2023 — https://www.theregister.com/2023/06/05/british_airways_boots_moveit/
- Personnel Today, “BBC, Boots and BA see employee data hit in MOVEit cyberattack,” 6 June 2023 — https://www.personneltoday.com/hr/moveit-cyberattack-zellis/
- Security Affairs, “British Airways, BBC and Boots impacted by the Zellis data breach,” 7 June 2023 — https://securityaffairs.com/147119/data-breach/zellis-data-breach-bbc-ba.html
- Vulnerability: CVE-2023-34362 (MOVEit Transfer SQL injection), patched by Progress Software.
Operational discretion — the ICC episode
- Justice Info, “How sanctions can weaponize US tech against the ICC,” March 2026 — https://www.justiceinfo.net/en/156691-how-sanctions-can-weaponize-us-tech-against-the-icc.html
- Techzine, “Microsoft denies having suspended any services to ICC,” June 2025 — https://www.techzine.eu/news/privacy-compliance/131996/microsoft-denies-having-suspended-any-services-to-icc/
- The Register, “Microsoft throws spox under the bus in ICC email flap,” 18 February 2026 — https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/
- Xinhua, “Microsoft email block of ICC prosecutor fuels Dutch alarm over U.S. tech dependence,” 21 May 2025 — https://english.news.cn/20250521/4a278fdce8324af59346ecf47ac407c9/c.html
- Also: Digital Watch Observatory summary — https://dig.watch/updates/microsoft-allegedly-blocked-the-email-of-the-chief-prosecutor-of-the-international-criminal-court
Policy drift — France’s SREN law and the Health Data Hub
- ActuIA, “Sensitive Data and Cloud Act: Microsoft France Admits It Cannot Oppose an American Injunction,” 25 July 2025 — https://www.actuia.com/en/news/sensitive-data-and-cloud-act-microsoft-france-admits-it-cannot-oppose-an-american-injunction/
Next in this series: Ecosystem Lock-up — how vendor ecosystems quietly undermine sovereignty at exactly the moment you try to take control of the stack.

