Suverenumas prasideda išjungimo mygtuku
Mygtukas skaidrėje nėra išjungimo jungiklis
2026 m. balandį Europos Komisija skyrė 180 mln. EUR vertės sutartį dėl suverenios debesijos keturiems teikėjams, aptarnaujantiems Sąjungos institucijas, įstaigas, tarnybas ir agentūras. Konkursas buvo vykdomas pagal „Cloud III“ dinaminę pirkimo sistemą. Aiškindama rezultatą, Komisija paaiškino ir už jo slypintį instrumentą: debesijos suverenumo sistemą su suverenumo veiksmingumo užtikrinimo lygiu ir bendru balu, sudarytu iš 48 kriterijų aštuoniose kategorijose, įskaitant strateginę, teisinę ir jurisdikcijos, duomenų ir DI, veiklos, tiekimo grandinės, technologinę, saugumo ir atitikties bei aplinkos tvarumo.
Tai įdomesnis įvykis, nei paprastai sufleruoja būdvardis „suverenus“. Konkursas turi paversti politinį žodį klausimais, į kuriuos gali atsakyti pirkimo dokumentai. Kas gali pasiekti duomenis? Kas gali valdyti platformą? Kas atsitinka, kai tiekėjas keičia savininką, kai keičiasi įstatymai, kai paslauga atšaukiama arba kai institucija nusprendžia, kad susitarimas nebetinka? Komisijos sistema neišsprendžia šių klausimų už kiekvieną pirkėją. Ji daro ką nors naudingesnio: pripažįsta, kad jie turi būti svarstomi kartu.
Pagunda suverenumą laikyti vieta. Padėkite serverius Europoje, pasirašykite su Europos dukterine įmone, sutartį pavaldykite Europos teisei, ir atrodo, kad problema išspręsta. Kiekvienas iš šių žingsnių gali būti svarbus. Nė vienas iš jų nėra visa esmė. Sistema gali būti fiziškai arti ją aptarnaujamų žmonių, o jos lemiami raktai, techninės priklausomybės, veiklos įgaliojimai ir teisinė rizika gali būti kitur. Europos adresas gali būti teisingas ir vis tiek būti neišsamus atsakymas.
Yra testas, kuris atskleidžia šią spragą. Paklauskite, kas atsitinka, kai organizacijai reikia sustoti. Ne todėl, kad sustojimas yra pageidautinas, ir ne todėl, kad tikimasi dramatiškos nesėkmės, o todėl, kad rimtos institucijos turi turėti galimybę pakeisti kryptį. Ar įgaliotas asmuo gali sustabdyti paslaugą? Ar organizacija gali patikrinti būseną, kuri bus sustabdyta? Ar ji gali išsaugoti įrodymus? Ar ji gali perkelti darbo krūvį? Ar kita komanda gali perimti darbą neprašydama pirmojo teikėjo likti būtinu? Jei atsakymas neaiškus, suverenumo teiginys vis dar yra tik brošiūra.
Štai kodėl suverenumas prasideda nuo išjungimo jungiklio. Jungiklis nėra teatrališkas raudonas mygtukas. Tai įgaliojimų, prieigos, žinių, įrangos, sutarčių ir alternatyvų grandinė. Jis turi veikti eilinį antradienį, dar niekam neparengus spaudos pranešimo. Likusioje šio straipsnio dalyje ši grandinė nagrinėjama per debesijos infrastruktūrą, Europos politiką ir nepatrauklią išėjimo inžineriją.
Penki žodžiai, kurie dažnai verčiami apsimesti vienas kitu
Nuosavybė yra pirmasis apsimetėlis. Ji nurodo, kas valdo akcijas, skiria valdybą ir gauna ekonominę naudą. Nuosavybė gali būti svarbi suverenumui, ypač kai savininkas kontroliuoja intelektinę nuosavybę, investicinius sprendimus arba ilgalaikę įmonės kryptį. Ji nėra tas pats, kas veiklos kontrolė. Vietos savininkų organizacija gali priklausyti nuo užsienio veiklos platformos. Viešoji paslauga gali neturėti praktinių galimybių pakeisti ją valdančią programinę įrangą. Dukterinė įmonė gali būti įsteigta vienoje šalyje, o jos lemiami sprendimai priimami kitur.
Vieta yra antroji. Duomenų buvimo vieta atsako į geografinį klausimą: kur konkrečiai duomenys, sistemos ar įrenginiai saugomi ar apdorojami pagal susitarimą? Šis atsakymas gali padėti užtikrinti teisinę atitiktį, atsparumo planavimą arba pagrįstą delsos biudžetą. Jis neatsako, kas gali administruoti aplinką, koks įstatymas gali įpareigoti teikėją, kokie subrangovai gali patekti į grandinę arba kas atsitinka, kai privilegijuotuosius kredencialus turi operatorius už tos vietos ribų.
Jurisdikcija yra trečioji. Ji susijusi su teisine tvarka, kuri gali pasiekti organizaciją, jos infrastruktūrą ar duomenis. Sutartis gali pasirinkti taikytiną teisę, tačiau ji negali panaikinti kitų teisinių galių. Paslauga gali būti teikiama iš Europos infrastruktūros ir vis tiek apimti teikėją, kuriam taikomos pareigos kitur. Esmė nėra paskelbti kiekvieną tarptautinę paslaugą neteisėta. Esmė yra nustoti traktuoti žymeklį žemėlapyje kaip teisinę analizę.
Veiklos įgaliojimai yra ketvirtieji. Tai praktinis gebėjimas priversti sistemą ką nors daryti arba nustoti daryti: patvirtinti leidimą, pakeisti raktą, izoliuoti tinklą, atkurti atsarginę kopiją, pakeisti politiką, pašalinti administratorių arba perduoti atsakomybę kitai komandai. Veiklos įgaliojimai gali būti deleguojami. Kai jie deleguojami, delegavimas turi būti matomas, apribotas ir grįžtamas. Priešingu atveju sutartis suteikia klientui nominalią kontrolę, o teikėjas išlaiko vienintelius žmones ir sąsajas, galinčius ja naudotis.
Išėjimas yra penktasis. Tai gebėjimas nutraukti vieną susitarimą ir tęsti reikiamą funkciją kitur arba infrastruktūroje, kurią kontroliuoja organizacija. Išėjimas nėra vien duomenų bazės atsisiuntimas. Jis gali apimti konfigūraciją, tapatybes, šifravimo raktus, modelius, konteinerius, audito įrašus, eiles, integracijas, licencijas, veiklos procedūras ir žinias, reikalingas veikiančiai paslaugai atkurti. Pažadas, kad duomenis galima eksportuoti, nėra pažadas, kad paslaugą galima atnaujinti.
Šie žodžiai priklauso kartu, tačiau jų nereikėtų suplakti. Nuosavybė be veiklos įgaliojimų yra nuosavybės dokumentas be rakto. Vieta be jurisdikcijos yra gatvės adresas be teisinės aprėpties žemėlapio. Veiklos įgaliojimai be išėjimo yra nuotolinio valdymo pultas, prijungtas prie mašinos, kurios niekas kitas negali suremontuoti. Suverenumas yra visų penkių tarpusavio ryšys, išbandomas tą akimirką, kai patogumas nustoja lemti sprendimą.
Išjungimo jungiklio testas
Naudingas išjungimo jungiklio testas prasideda sąmoningai neįspūdinga instrukcija: sustabdykite šią sistemą ties apibrėžta riba, apibrėžtu būdu, vadovaujant nustatytai institucijai. „Ši sistema“ turi būti konkreti. Ar tai viena paslauga, nuomininkas, apdorojimo užduotis, duomenų srautas, administratoriaus paskyra, modelio galinė stotis ar visa veiklos galimybė? Teikėjas gali išjungti galinę stotį, o duomenys, kopijos ir privilegijuoti keliai tęsiasi kitur. Klientas gali atšaukti sutartį ir sužinoti, kad vienintelis galimas eksportas yra įrašų rinkinys be naudingos konfigūracijos.
Pirmiausia paklauskite, kam leista įsakyti sustabdymą. Atsakymas turėtų būti vaidmuo, o ne žmogaus atmintis. Vaidmuo gali būti priskirtas, patikrintas ir pakeistas. Jis turėtų turėti aiškų suveikimo mechanizmą, eskalavimo kelią ir sprendimo įrašą. Viešojoje įstaigoje įgaliojimai gali būti padalyti tarp paslaugos savininko, saugumo, teisinės atsakomybės ir budinčio pareigūno. Padalijimas nėra trūkumas. Jis tampa trūkumu, kai visi mano, kad kas nors kitas gali veikti.
Tada paklauskite, kuris kredencialas ar mechanizmas iš tikrųjų atlieka sustabdymą. Dokumentuota procedūra, kuri baigiasi „susisiekite su palaikymo tarnyba“, yra eskalavimo kelias, o ne išjungimo jungiklis. Palaikymo tarnyba gali būti tinkama kontroliuojamam perkėlimui, tačiau kritinei paslaugai taip pat reikia vietinio arba nepriklausomai kontroliuojamo būdo sistemai pervesti į saugią būseną. Tai nereiškia, kad kiekvienas klientas turėtų turėti fizinį maitinimo mygtuką. Tai reiškia, kad organizacija turi žinoti savo įgaliojimų ribas, teikėjo įgaliojimus ir momentą, kada reikia išorinio atsako.
Next ask what remains after the stop. A safe stop may preserve logs, retain evidence for a defined period, close sessions, revoke credentials, prevent new writes and keep a read-only copy available for investigation. It may also create a dangerous state if a dependent process continues to send data into a service that is no longer being monitored. Stopping one component is not the same as stopping the capability. The dependency map matters more than the colour of the button.
Finally ask whether the organisation can resume the function without returning to the same dependency by default. A service may be stopped for a short containment action and then restarted. That is useful. Sovereignty requires a second path as well: a prepared route to another provider, a local environment, a known manual process or a deliberately reduced service. The alternative can be slower or less elegant. It cannot exist only as a sentence in a risk register.
The off-switch test therefore has five parts: authority, mechanism, evidence, dependency and alternative. It is an institutional test, not a product feature. A supplier can provide excellent tools and still fail the test if the customer cannot exercise them. A customer can own a contract and still fail if nobody has practised the procedure. An organisation that has rehearsed the test may discover weaknesses early, when they are still procurement and engineering problems rather than public emergencies.
Control is a stack, not a sticker
Imagine a system as a stack of rooms. At the bottom is the physical layer: buildings, power, cooling, network paths and hardware. Above it sit the technical layers: firmware, operating systems, virtualisation, storage, databases, identity and application code. Above those are the operational layers: people, procedures, monitoring, incident response and release management. Alongside them runs a legal and economic layer: ownership, contracts, licences, jurisdiction, financing and the ability to purchase an alternative.
The stack metaphor is not a claim that all systems have five neat floors. It is a way to ask a more precise question than “is this sovereign?” Control can be strong in one room and weak in another. An institution may have the right to inspect an application while having no view of the physical administration path. It may hold encryption keys while lacking the ability to replace the hardware that keeps the key service alive. It may have a contractual exit clause while carrying an operational dependency on a team that only the provider employs.
There is no virtue in pretending that every layer must be European in the same way. Europe’s digital economy depends on international supply chains, research, standards and markets. Strategic autonomy is not a fantasy of total self-sufficiency. The European Commission’s own policy definition speaks of the ability to act independently while reducing reliance on non-EU providers. Acting independently can mean having a credible choice, not manufacturing every component behind a national fence.
The practical distinction is between dependence that is visible and bounded, and dependence that is mistaken for control. A buyer can decide that a particular processor, software component or external service is acceptable. The decision should include the reason, the compensating measures, the replacement route and the authority to revisit it. A dependency that is recorded can be governed. A dependency hidden behind a European label will be discovered only when the label stops opening doors.
The stack also explains why a sovereignty score needs more than ownership. The Commission’s 2026 framework places strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability criteria beside one another. A list like this does not magically produce a sovereign service. It does acknowledge that control is distributed. That is already a better starting point than a single badge.
For engineers, the stack invites a dependency inventory. For procurement teams, it invites questions about subcontractors, keys, formats, interfaces, support and migration. For lawyers, it invites a map of legal reach that follows the provider and the infrastructure rather than the marketing name. For leaders, it makes a quiet point: the most expensive dependency is often the one that everyone thought had already been dealt with.
Location is useful, and insufficient
A data centre is a real place. Its walls affect physical security, energy use, network latency, labour arrangements and the resilience of a service. A residency requirement can prevent some transfers and can make an audit more concrete. It can also be a sensible expression of a public body’s legal and political responsibility. There is no need to sneer at geography to make the control point.
The mistake is asking geography to answer all the other questions. A server in Rotterdam does not, by itself, tell a buyer who has administrative access. A storage bucket in Milan does not say which telemetry is copied to a support system. A European subsidiary does not disclose the jurisdiction of the group that supplies its control plane. The location of a building and the reach of an organisation are related facts, not interchangeable facts.
The Data Act makes part of this distinction explicit. Article 28 requires providers of data processing services to make available the jurisdiction to which the infrastructure used for a service is subject, together with a general description of measures concerning international governmental access to or transfer of non-personal data where that could conflict with Union or Member State law. The requirement is valuable because it turns a vague assurance into information a customer can put in a file. It is not a guarantee that no authority will ever ask for access, and it is not a replacement for a customer’s own legal and technical assessment.
Location also changes over time. A provider can move a workload, add a subcontractor, introduce a support path, change a control-plane design or alter its ownership. A residency statement that was accurate on the day of signature can become stale. Sovereignty therefore needs a change signal: who is notified, which change triggers review, and who can pause the service while the review happens? Without that signal, a location claim is a snapshot masquerading as a property.
Įsivaizduokite hipotetinę Europos mokslinių tyrimų organizaciją, kuriai reikia, kad pagrindinis duomenų rinkinys liktų Sąjungoje. Šis reikalavimas gali būti įvykdytas, kai pagalbinis darbo srautas siunčia diagnostinę medžiagą į trečiąją šalį, kai tiekėjo valdoma tapatybės paslauga administruoja klasterį arba kai nuosavas formatas padaro pakeitimą neįmanomą. Nė viena iš šių galimybių nėra teigiama kaip faktas apie konkrečią organizaciją. Jos yra priežastis, dėl kurios vietos kontrolė turėtų būti sujungta su prieigos žemėlapiu, jurisdikcijos žemėlapiu ir išėjimo repeticija.
Sąžiningesnis teiginys yra paprastas: vieta gali sumažinti tam tikrą rizikos klasę. Ji negali panešti viso suverenumo argumento. Pastatas yra sluoksnis. Kontrolė yra visuma.
Jurisdikcija nėra išnaša
Jurisdikcija į pokalbį įtraukiama tada, kai pažadas susiduria su galia. Sutartyje gali būti nurodyta, kur bus nagrinėjami ginčai ir kuri teisė reglamentuoja santykius. Tai svarbu nuspėjamumui ir vykdymui. Tai nereiškia, kad tiekėjas, jo patronuojanti įmonė, jo darbuotojai ar jo infrastruktūra yra nematomi bet kuriai kitai teisinei sistemai. Pirkėjo klausimas nėra tai, ar galima įvardyti vieną jurisdikciją. Klausimas yra, kokie teisiniai keliai gali pasiekti susijusius žmones, sistemas ir duomenis ir ką tiekėjas turėtų daryti, jei tie keliai būtų naudojami.
Tai nėra argumentas, kad kiekvienas užsienio ryšys būtų laikomas draudžiamu. Tai argumentas, kad tautybės santrumpa būtų pakeista dokumentuota analize. Tiekėjas gali turėti Europos įmonę, Europos veiklą ir tiekimo grandinę, kertančią kelias sienas. Pirkėjas gali sutikti su tokiu išdėstymu, nes paslauga yra atspari, prieigos kontrolė yra stipri, susiję duomenys yra riboti ir yra paruoštas alternatyvus sprendimas. Sprendimas yra gintinas, kai priklausomybė ir liekamoji rizika yra matomos.
Žodis kontrolė čia taip pat reikalauja atsargumo. Tiekėjas gali teigti, kad klientas kontroliuoja savo duomenis, nes klientas pasirenka leidimus. Tai gali būti tiesa paslaugos viduje. Tai automatiškai nereiškia, kad klientas kontroliuoja tiekėją, platformos priežiūros kelią ar teisinį atsaką į išorinį įsakymą. Žodis turėtų būti patikslintas: prieigos kontrolė, raktų kontrolė, konfigūracijos kontrolė, operacijų kontrolė arba verslo sprendimo kontrolė. Tikslumas yra mažiau įspūdingas nei suverenumo logotipas, tačiau jis geriau atlaiko auditą.
Komisijos sistema teisinius ir jurisdikcijos klausimus išdėsto greta operacinių ir tiekimo grandinės klausimų. Toks išdėstymas yra svarbus. Teisinės rizikos negalima sumažinti iki pastraipos sutartyje, o techninės kontrolės negalima sumažinti iki diagramos. Jei sistema turi palaikyti viešąją funkciją, institucijai reikia pakankamai įrodymų, kad paaiškintų ir kaip sistema veikia, ir kurios institucijos gali jai daryti įtaką. Įrodymai gali būti neišsamūs. Jie neturėtų būti išgalvoti.
Praktinėje jurisdikcijos byloje turėtų būti nustatyti paslaugų grandinės teisiniai subjektai, susijusios infrastruktūros vieta ir vaidmuo, tiekėjo darbuotojams ir subrangovams prieinami prieigos keliai, tiekėjo atskleisti taikytini ir reglamentuojantys įstatymai bei pranešimo ir atsako tvarka dėl vyriausybės prašymų. Joje taip pat turėtų būti nurodyta, ką klientas darys, jei atsakymai pasikeis. Paskutinis sakinys yra ta vieta, kur suverenumas pradeda tapti veiklos, o ne aprašomuoju.
Komisijos viešųjų pirkimų eksperimentas
Komisijos suverenaus debesijos viešieji pirkimai yra naudingi, nes jie daro žodį stebimą. Viešame paaiškinime teigiama, kad keturi tiekėjai buvo atrinkti 180 mln. EUR vertės sutarčiai, aptarnaujančiai Sąjungos subjektus. Jame aprašomos dvi viena kitą papildančios priemonės: suverenumo veiksmingumo užtikrinimo lygis, apibrėžiantis duomenų suverenumo, technologinės autonomijos ir visiško suverenumo ribas, ir bendras balas, pagrįstas 48 apibrėžtais kriterijais, suskirstytais į aštuonias kategorijas.
There is a small but important discipline in that wording. The framework is an evaluation instrument. It does not turn a provider into a sovereign object by declaration. A score can make trade-offs visible, help a buyer compare offers and create a record of why an award was made. It can also be gamed or become stale if nobody checks the evidence behind it. The sensible question is not whether the framework is the final answer. It is whether the criteria survive contact with operations.
Take the category called operational sovereignty. It should prompt questions such as who can change a network route, who can rotate a key, who can read an incident log, how quickly a customer can take over a function and which actions require provider participation. Those are not abstract qualities. They can be demonstrated in a controlled exercise. If the exercise is impossible because the provider cannot expose the relevant state or because the customer has no authority to initiate it, the weakness is part of the score, not an inconvenient detail to be left in an appendix.
The same is true of supply-chain and technological categories. A buyer does not need to demand an impossible purity test. It does need to know which dependencies are essential, which can be substituted, which have contractual or technical lock-in, and what an interruption would look like. “We have a European support team” and “we can continue this function when a critical upstream component is unavailable” are different claims. The first is about people. The second is about resilience and choice.
Public procurement is particularly well suited to this work because a tender can demand evidence before a service becomes the default. A tender can ask for a portable format, a current dependency register, a change-notification procedure, an exit rehearsal and an authority matrix. It can score answers and reject a service that cannot show them. It can also pay for the capacity to maintain the alternative, because an exit that exists only in a dormant document will decay.
The Commission’s publication presents its framework as a benchmark for public and private organisations. That is an invitation, not an endorsement that every organisation should copy every weight. A small service and a continent-wide platform will have different risks. The method worth carrying across is the habit of decomposing sovereignty into criteria, evidence and thresholds. Procurement can say no. That is one of the few powers that becomes weaker after deployment.
Exit is an engineering property
Cloud contracts often describe exit as if it were a polite final paragraph. The Data Act treats it as a process. Article 23 requires providers of data processing services to remove obstacles that inhibit a customer from terminating a contract, concluding a new contract, porting exportable data and digital assets, achieving functional equivalence where applicable, or unbundling services where technically feasible. Articles 25 to 30 then spell out contract, information, cooperation, charges and technical obligations.
The details are unusually practical. In the ordinary case, a contract must provide for a maximum notice period of two months and a mandatory transitional period of no more than 30 calendar days, during which the provider continues the service and supports continuity. If the provider claims that the 30-day period is technically unfeasible, it has to notify the customer within 14 working days, justify the claim and indicate an alternative transitional period of no more than seven months. The customer is given a retrieval period of at least 30 calendar days after the transitional period, and the contract has to address erasure after a successful switch.
Article 29 also sets the direction of travel for switching charges. From 12 January 2027, providers may not impose switching charges for the switching process. During the transition, reduced charges may be imposed only within the limits set by the Regulation, and prospective customers must be told what fees and penalties may apply. Article 30 addresses open interfaces, interoperability specifications and machine-readable export. These are not decorative details. They are the pieces from which a replacement service has to be assembled.
A legal right is not the same thing as a rehearsed path. A customer can receive a compliant export and still lack the people, tools or time to restore the service. Data can be portable while the meaning of an identifier is not. A model can be copied while its evaluation set, prompt policy, access rules and monitoring history remain behind. A container can be moved while the identity and key-management assumptions prevent it from starting. The law improves the floor. Engineering decides whether anyone can walk across it.
That is why exit should be tested in layers. Start with a sample of exportable data and reconstruct it in a separate environment. Then restore the identities and permissions with least privilege. Rebuild the service from documented configuration rather than an engineer’s memory. Replay representative workloads and compare the results, including the cases that should fail. Check that audit records retain their meaning. Run the exercise again after a material change. If the exercise requires an undisclosed provider intervention, record that dependency instead of calling the exercise independent.
The phrase functional equivalence also deserves restraint. The Data Act defines it around a materially comparable outcome for shared features in the same service type. It does not promise that two providers have identical architectures, prices, performance or support. A buyer should specify what must remain equivalent, what can degrade temporarily and what is allowed to change. An exit route that preserves every convenience may be impossible. An exit route that preserves the public function can be sufficient, provided the institution has chosen that trade-off in advance.
The off switch belongs to an institution
It is tempting to place the off switch in a product demo. Press a control, watch a green indicator turn grey, and call the system governable. Real authority is more awkward. It sits in an institution with job descriptions, delegations, holidays, competing priorities and people who may not know that they are the person expected to act.
That does not mean that every employee should be able to stop every system. It means the authority should be designed. The service owner decides what the function is for. Security can identify a containment trigger. Legal and privacy teams can identify constraints on evidence and access. Operations can execute the procedure. Leadership can resolve a conflict between continuity and withdrawal. The roles can be combined in a small organisation, but the decisions still need to be explicit.
Consider a hypothetical regional public service that uses a hosted platform to process applications. Nobody has to invent a failure story to see the governance question. If a supplier changes a critical access path, who reviews it? If monitoring shows an unexplained behaviour, who may pause new submissions? If the contract is terminated, who owns the export, who verifies that it is complete, and who decides whether a manual process is safe enough to run while a replacement is built? A policy that names the roles before the pressure arrives is more useful than a post-incident promise to improve coordination.
The same discipline applies to automated systems. An AI component can be stopped while the surrounding workflow continues to produce decisions from cached outputs, fallback rules or human assumptions. The organisation therefore needs to define the unit of authority. Is the off switch for the model, the decision service, the queue, the publication step or the entire process? A narrow switch can be safer than a total shutdown, but only if its boundary is known and its effect is observable.
Evidence is part of the institutional switch. A stop action should leave a record of who acted, under which authority, at what time, with what observed state and what next step. The record is not bureaucratic decoration. It lets the organisation distinguish a deliberate containment action from a silent degradation and lets a replacement team understand what it has inherited. This is the same reason the Data Act asks providers to give information about formats, procedures and limitations. A system that cannot describe its state cannot be transferred responsibly.
There is also a human dignity point. When organisations say that a provider is indispensable, they often mean that a small number of people understand the arrangement. That is a knowledge dependency, not a fact of nature. Documentation, training, paired operations and regular exercises can make authority less personal and more durable. The result may look less magical. It is usually more resilient.
A sovereignty file that can survive a meeting
A sovereignty file should be something a procurement officer, engineer, lawyer and accountable leader can all read without translating the document into four different private languages. It should not be a 100-page assurance pack that answers every question except the one a decision-maker is about to ask. A compact file can point to deeper evidence while making the control boundary visible.
Start with the service definition. Name the function, the data, the users, the decisions or actions supported, the acceptable interruption and the consequences of an unsafe continuation. Mark what is critical and what is merely convenient. This prevents the organisation from negotiating sovereignty for a dashboard while overlooking the identity service that lets anyone reach it.
Then record the control map. For each material component, identify who owns it, who operates it, who can inspect it, who can change it, who can stop it, and who can replace it. Use the actual entity and role names from the contract and operating model. If a field reads “provider” or “customer” without a named responsibility, it is an invitation to ask another question.
Record the legal and jurisdictional map next. Include the contracting entities, relevant provider entities, infrastructure jurisdictions disclosed under the arrangement, applicable subcontractors, access routes and notification procedures. State where the evidence is current and when it must be reviewed. A map with a date is more honest than an evergreen assurance sentence.
Išėjimo skyriuje turi būti inventorius, o ne tik ketinimas. Išvardykite eksportuojamus duomenis, skaitmeninį turtą, konfigūraciją, tapatybes, raktus, žurnalus, modelius, vertinimo medžiagą, licencijas ir priklausomybes, kurių negalima perkelti. Kiekvienam elementui nurodykite jo formatą, savininką, gavimo būdą, tikrinimo testą ir saugojimo arba ištrynimo taisyklę. Jei elemento eksportuoti negalima, paaiškinkite kodėl ir apibūdinkite alternatyvą. Esmė ne nubausti teikėją už saugomų komercinių paslapčių turėjimą. Esmė neleisti supainioti kliento darbinių galimybių su teikėjo vidine infrastruktūra.
Galiausiai pridėkite pratybų įrašą. Jame turi būti nurodyta data, apimtis, dalyviai, prielaidos, pastebėti trūkumai, taisomieji veiksmai ir kitos peržiūros priežastis. Nedidelio masto bandomasis išėjimas gali būti informatyvesnis nei didelis teorinis planas. Pratybos gali atskleisti, kad formatas techniškai prieinamas, bet jį lėta interpretuoti, kad raktas yra perkeliamas, bet jo negali naudoti alternatyvi aplinka, arba kad institucija egzistuoja popieriuje, bet jos nepasieksite ne darbo valandomis. Tai išsprendžiami atradimai. Jie kur kas malonesni nei netikėtumai.
Faile taip pat turi būti atsisakymo sąlyga. Kokie įrodymai paskatintų organizaciją atsisakyti paslaugos, atidėti diegimą ar apriboti siunčiamus duomenis? Čia suverenumas tampa viešųjų pirkimų pasirinkimu, o ne noru. Pirkėjui nereikia atmesti kiekvienos priklausomybės. Jam reikia žinoti, kuri priklausomybė padarytų paslaugą nepriimtiną ir kas turi įgaliojimus tai pareikšti.
Kiek kainuoja suverenumas, o kiek priklausomybė
Suverenumas nėra nemokamas. Kontroliuojamiems raktams reikia žmonių ir procedūrų. Perkeliami formatai gali apriboti patentuotos funkcijos patogumą. Perteklinis pajėgumas kainuoja pinigus dar prieš jam prireikiant. Alternatyvus teikėjas gali būti mažiau išbaigtas. Vietinis veikimo kelias gali būti lėtesnis. Viešoji įstaiga, reikalaujanti įrodymų, gali sulaukti mažiau pasiūlymų ir ilgiau apsispręsti. Tai realios išlaidos, ir jas slėpti po vėliava yra ne mažiau nesąžininga nei slėpti priklausomybę po nuolaida.
Svarbus palyginimas yra ne suverenumas su pasaulyje be trinties. Tai apgalvota išlaida prieš neįkainotą priklausomybę. Paslauga, kurią pigiau įdiegti, gali būti brangi tikrinant, brangi migruojant arba neįmanoma sustabdyti be pasekmių visuomenei. Techniškai puikus teikėjas vis tiek gali sukelti koncentracijos riziką, jei klientas negali pakeisti kritinės sąsajos. Vietiniu būdu valdomas kelias šiandien gali kainuoti daugiau, bet išsaugoti galimybę rinktis rytoj. Nė vienas pasirinkimas nėra automatiškai teisingas. Įstaiga turėtų sugebėti paaiškinti, kokias išlaidas ji prisiėmė.
ENISA debesijos rizikos vertinimas yra pakankamai senas, kad būtų išgyvenęs ne vieną madingą architektūrą. Tai dalis jo naudingumo. Jo sistema traktuoja debesų kompiuteriją kaip verslo ir technologijos modelį su nauda ir rizika, įskaitant užsiblokavimą ir teisinę riziką, ir rekomenduoja vertinti šią riziką, o ne manyti, kad debesis yra arba išlaisvinimas, arba pavojus. Tokio paties požiūrio reikia ir suverenumui. Klausimas ne tas, ar susitarimas yra grynas. Klausimas, ar jo priklausomybės yra žinomos, apribotos ir pakankamai pakeičiamos atitinkamai funkcijai.
Pertekliškumas dažnai suprantamas klaidingai kaip dviejų vienodų kopijų turėjimas. Kartais geresnė alternatyva yra kitoks įgyvendinimas, rankinis atsarginis variantas arba sumažinta paslauga, išsauganti svarbiausią viešąją funkciją. Pasirinkimas priklauso nuo pertrūkio pasekmių. Mokslinis darbo krūvis gali pakęsti atidėtą vykdymą. Viešosios informacijos paslaugai gali prireikti statinio publikavimo kelio. Su sauga susijusiam darbo procesui gali prireikti žmogiškojo patikros punkto ir išbandytos procedūros, o ne antro identiško galinio taško. Suverenumas yra galimybė pasirinkti atsarginį variantą dar prieš pagrindinei sistemai pasirenkant jį už jus.
There is a social cost too. If only a few people can operate a system, the organisation has bought a dependency on their memory. If public procurement treats every departure from the incumbent as irresponsible, it teaches the market that exit is theatre. If institutions fund alternatives only until the first tender is complete, they create a demonstration rather than capacity. Paying for operating knowledge, interoperability and maintenance is less exciting than announcing a platform. It is also how choices survive the second budget cycle.
Our small footnote
At Dweve, our public report The Sovereignty Illusion makes a related argument through five practical doors: ownership, technology, capital, infrastructure and legal exposure. The report is our own analysis, not a legal standard and not a substitute for the Commission’s procurement framework or the Data Act. Its value here is simply the habit it encourages: when somebody says that a system is sovereign, ask which door carries the control and which door remains open. That is the scale at which we prefer to discuss our own work, after the evidence and before the pitch.
The test happens before the emergency
The most revealing moment for sovereignty is rarely the launch. Launches are full of prepared diagrams, named teams and favourable weather. The revealing moment is a change of course: a contract must end, a provider must be challenged, a legal reach must be reviewed, a dependency must be replaced, or an operator must stop a function before all the facts are comfortable.
That is why the off switch is a better starting point than the flag. It asks for authority rather than atmosphere. It asks what the organisation can inspect, not what the provider can promise. It asks whether data and digital assets can move, whether the function can continue, and whether the evidence will survive the move. It turns sovereignty into a set of rehearsable actions.
The European Commission’s 2026 framework shows that public procurement can make these actions legible. The Data Act shows that switching and jurisdictional information can be duties rather than favours. ENISA’s risk work reminds us that lock-in and legal exposure are not new surprises, even when the architecture changes its name. None of these sources says that Europe can operate without dependencies. They offer something more serious: a way to decide which dependencies are acceptable and what happens when they are not.
A European institution does not need to own every chip, write every operating system or build every service to act with sovereignty. It needs to retain a credible ability to understand the arrangement, set limits, change the terms, stop the unsafe path and continue the essential function. Sometimes that means choosing a European provider. Sometimes it means an open interface, a separate key holder, a second operator, a manual route or a smaller service. The answer belongs to the risk and the public responsibility, not to a slogan.
Before the next sovereign-cloud announcement, ask five plain questions. Who can stop this? Who can see what happened? Who can change it? Where can it move? What can replace it? If the answers are written, tested and owned, the word sovereignty may be doing useful work. If the answers end at a logo and an address, the system has not yet found its off switch.
Sources
- Sovereign Cloud Framework explained, Europos Komisija, Skaitmeninių paslaugų generalinis direktoratas.
- Strengthening Europe’s Tech Sovereignty, Europos Komisija, Europos skaitmeninės ateities formavimas.
- Regulation (EU) 2023/2854 (Data Act), EUR-Lex, ypač VI skyrius apie perėjimą tarp duomenų apdorojimo paslaugų.
- Cloud Computing Risk Assessment, Europos Sąjungos kibernetinio saugumo agentūra.
- The Sovereignty Illusion, Dweve.