The Hidden Layers of Dependency - cloud sovereignty architecture
- Erik Kling

- May 20
- 6 min read

Cloud Sovereignty Part 2
The Hidden Layers of Dependency
— — —
Most cloud sovereignty discussions still operate at the surface layer.
Data residency.
Regional hosting.
Compliance frameworks.
Procurement announcements.
European cloud branding.
But sovereignty is not determined at the surface.
It is determined by the dependency architecture underneath the visible system.
This is where the discussion becomes much more serious.
Because modern dependency is no longer singular. It is layered.
And most organizations still evaluate only the visible layer.
That creates dangerous strategic blindness.
— — —
Europe Is Moving — But The Real Question Has Changed
In Part 1 of this series, I introduced the core argument: sovereignty is architectural, not geographic. This post goes deeper into the specific layers where dependency actually accumulates — using the same cases as structural proof.
Europe is now moving aggressively into sovereign cloud and AI infrastructure.
The European Commission recently awarded a €180 million sovereign cloud framework to four European provider groups, including:
— STACKIT
— Scaleway
— Post Telecom with OVHcloud and CleverCloud
— Proximus with S3NS, Thales/Google Cloud, Clarence, and Mistral
At first glance this appears straightforward: Europe is building sovereign cloud capability.
But the structure of the consortiums exposes something much more important.
Sovereignty is no longer binary. It is layered.
A non-European technology layer can now exist inside a European governance wrapper while still participating in a sovereign framework.
That changes the entire discussion.
Because the critical question is no longer: "Is the infrastructure local?"
The critical question is: "Which layers remain externally dependent?"
— — —
The Architecture Stack Of Dependency
Modern cloud and AI systems operate through multiple interconnected layers. Each layer creates a different form of leverage. And each layer creates a different form of dependency.
Layer 1 — Physical Infrastructure
This is the visible layer:
— data centers
— cooling
— fiber
— subsea cables
— land
— energy access
— compute clusters
This layer matters enormously. But it is only the foundation.
A workload operating inside Europe can still remain structurally dependent on external orchestration, AI tooling, software ecosystems, and semiconductor supply chains.
The infrastructure may appear sovereign. The operational architecture may not be.
Layer 2 — Semiconductor Dependency
This is one of the most concentrated layers in the global system.
AI sovereignty is impossible without compute sovereignty. And compute sovereignty is impossible without semiconductor access.
Europe partially controls one of the most strategically important chokepoints in the world through ASML. Without EUV lithography systems, advanced AI chip manufacturing becomes nearly impossible.
This gives Europe enormous strategic leverage. But the system remains globally interdependent.
Because advanced semiconductors also depend on:
— foundries
— packaging
— memory
— substrate supply
— rare materials
— export regimes
— GPU allocation systems
A region can control one strategic layer while remaining dependent across several others. That is the architecture problem.
Nvidia And The AI Compute Concentration Risk
The OECD cites estimates that NVIDIA controls more than 80% of the AI GPU market.
That means a large portion of global AI infrastructure now depends on:
— a concentrated hardware ecosystem
— proprietary software stacks
— CUDA dependencies
— allocation decisions
— manufacturing concentration
This is not merely a supply chain issue. It is a future leverage issue.
Because organizations increasingly build workflows, models, applications, AI operations, and inference systems around a single compute architecture.
Over time the dependency becomes operational gravity.
The organization stops asking: "Can we leave?"
And starts asking: "How expensive would survival become if we had to?"
That is structural dependency accumulation.
Layer 3 — Orchestration Control
This is one of the least understood control layers.
Who controls:
— Kubernetes orchestration
— automation systems
— provisioning
— deployment pipelines
— infrastructure APIs
— cloud control planes
— AI workflow management
— operational tooling
Because this layer determines operational sovereignty. Not merely hosting sovereignty.
An organization may physically host infrastructure locally while operational logic remains externally dependent. That creates structural asymmetry. The infrastructure exists locally. The control logic does not.
Germany: Sovereign Operations Built On External AI Layers
Germany now provides one of the clearest real-world examples.
SAP and OpenAI announced "OpenAI for Germany" through SAP's Delos Cloud infrastructure. The initiative is positioned as sovereign AI capability for the German public sector.
But the stack explicitly relies on:
— Microsoft Azure (as the underlying infrastructure platform for Delos Cloud)
— OpenAI model ecosystems
This is not failure. It is evidence of layered sovereignty.
The governance layer may become sovereign. The operational layer may become European. The underlying AI and cloud infrastructure layers may remain externally concentrated.
That distinction matters enormously. Because if strategic capability depends on external AI stacks, future industrial leverage can migrate externally even while local infrastructure expands.
Layer 4 — API Dependency
Modern dependency increasingly lives inside APIs. Not hardware. Not even data centers.
APIs now shape:
— workflows
— authentication
— integrations
— monitoring
— AI tooling
— automation
— operational processes
— developer ecosystems
Over time APIs become invisible lock-in architecture. The longer the integration history, the harder reversibility becomes.
This is why the European Union introduced interoperability and switching provisions inside the EU Data Act.
That is not a technical detail. It is an admission that reversibility has become strategic infrastructure.
Because once systems cannot switch:
— they lose negotiation leverage
— they lose operational freedom
— they lose strategic flexibility
And eventually: they lose control.
France And The Health Data Hub Reversal
France provides one of the strongest — and most recent — examples of reversibility architecture becoming strategic policy.
The French Health Data Hub was originally hosted on Microsoft Azure following a 2019 decision made without a competitive tender, which drew sustained legal and political scrutiny. The controversy centred on U.S. jurisdiction exposure, sensitive health data, dependency risk, and long-term sovereignty concerns.
In April 2026, France formally selected Scaleway to replace Microsoft Azure as host of the Health Data Hub — a selection process involving more than 350 technical criteria. The migration is expected to be completed between late 2026 and early 2027.
This was not merely a cloud migration. It was a recognition that infrastructure decisions create future strategic consequences.
The French state effectively concluded: certain dependency layers had become strategically unacceptable.
That is exactly the type of architectural realization most organizations reach too late.
And the fact that this decision was made just weeks ago — not years ago — makes it more significant, not less. It signals that the shift from compliance to sovereignty as operational doctrine is happening now.
Layer 5 — AI Stack Dependency
The AI layer is now becoming the decisive layer.
Who controls:
— foundation models
— inference infrastructure
— vector databases
— AI middleware
— agent systems
— operational memory
— training pipelines
— optimization layers
— developer ecosystems
Because AI systems are no longer productivity tools. They are becoming civilization infrastructure.
Organizations integrating deeply into external AI ecosystems may unintentionally transfer future operational leverage outside their own architecture.
Especially once workflows, institutional knowledge, operational decision-making, automation, customer interaction, and industrial processes become AI-mediated.
This creates dependency that becomes increasingly difficult to reverse.
The Nordic Compute Reality
The Nordics reveal another important truth: AI is physical. Not virtual.
LUMI and broader Nordic AI infrastructure strategies are built around renewable power, cooling efficiency, grid stability, and geographic conditions.
This matters because AI ultimately becomes electricity, thermodynamics, cooling, energy allocation, and infrastructure geography.
The cloud appears virtual. The dependency architecture is deeply physical.
The UK And The Architecture Layer
The United Kingdom demonstrates another overlooked layer: architectural intellectual property.
Arm Holdings powers large portions of mobile computing, embedded systems, IoT, edge infrastructure, and increasingly AI systems.
ARM's influence proves something important: control over architecture standards can become more powerful than ownership of infrastructure itself.
The future digital system will increasingly be controlled by standards, orchestration, interfaces, developer ecosystems, AI architectures, and operational frameworks.
Not merely by buildings and servers.
— — —
The Real Question Is Reversibility
This is where the entire discussion converges.
The objective is not complete independence. No major system operates without dependencies.
The objective is reversibility.
Can the system:
— switch providers?
— replace orchestration layers?
— diversify compute exposure?
— migrate AI models?
— separate infrastructure layers?
— reroute operational dependencies?
— preserve leverage under pressure?
Because sovereignty without reversibility is fragile.
And compliance without optionality is dependency.
The Real Cloud Sovereignty Question
The real question is no longer: "Where is the data?"
The real questions are:
— Which layer actually controls the system?
— Which dependencies are acceptable?
— Which dependencies are strategically irreversible?
— Can the organization still negotiate?
— Can the state still decide?
— Can the industrial base still operate under pressure?
— Can the system still move?
That is the architecture discussion most organizations still avoid.
Because once optionality disappears, leverage transfers elsewhere.
Usually permanently.
The Next Industrial Era
The next industrial era is already forming around:
— AI infrastructure
— semiconductors
— orchestration systems
— APIs
— compute allocation
— energy systems
— jurisdiction
— identity infrastructure
— operational control layers
Most organizations still evaluate these systems independently.
But the leverage emerges from the architecture connecting them.
This is why the real issue is not cloud migration.
The real issue is control architecture.
— — —
Erik Kling
AXISYNC Partners
Part of an ongoing architectural doctrine on systems, infrastructure, and long-term strategic control. Across all domains, invisible structures ultimately determine visible outcomes.
Architecture determines optionality. Optionality determines leverage. Leverage determines control.
Explore: Axisync Partners — AXYNAO — Erik Kling Art



Comments