Digital sovereignty has become a battle cry. One camp interprets this as meaning to rid the company of everything American. The other sees it as a subsidy scheme for second-rate European software. Both are mistaken, and on the same point: they confuse sovereignty with origin.
Sovereignty is an architectural property. It is measured by the speed with which you can replace a provider without your business even noticing. The flag on the language model is of secondary importance.
Small and medium-sized enterprises have long sensed that something is amiss here: According to the Bitkom Cloud Report 2026, 85 per cent of German companies believe that Germany is too dependent on US providers when it comes to cloud technologies. 71 per cent source cloud services from the US, but only 8 per cent would choose to do so voluntarily. At the same time, only 12 per cent would be willing to pay significantly more for a secure German alternative. So the moral appeal isn’t getting through. Sovereignty has to be cost-effective.
At the AI layer, this is feasible, for one simple reason: Unlike when migrating from a hyperscaler, you don’t have to discard anything here. You simply need to take control of the right layers yourself and ensure that the interchangeable ones remain interchangeable.
What digital sovereignty in AI means – and what it doesn’t
Three capabilities make an AI setup sovereign. Firstly, interchangeability: you can swap models or providers without having to rebuild processes. Secondly, data control: prompts, knowledge bases and agent memories are within your control. Thirdly, legal certainty: your setup can withstand even a legal landscape that changes across the Atlantic.
What autonomy does not mean: boycotting US technology. GPT and Claude are among the very best for many tasks, and anyone who ignores them on principle pays a daily productivity tax. Conversely, anyone who embeds them uncritically into every process will end up paying a ransom later on. Both scenarios are avoidable.
Microsoft, of all companies, has demonstrated why the question of location alone solves nothing. June 2025, hearing in the French Senate: Anton Carniaux, General Counsel of Microsoft France, is asked under oath whether he can guarantee that data belonging to French citizens will never be transferred to the US government without the consent of the French authorities. His answer: No, he could not guarantee that. A statement that undermines every EU data centre brochure. The basis for this is the CLOUD Act of 2018: US providers must hand over data on US orders, regardless of where the server is located.
In short: if the data centre is in Frankfurt but the parent company is in Redmond, then the parent company has access – not the location. An EU data centre operated by a US provider is a data residence, not a matter of sovereignty.
The four layers of your AI stack and where the lock-in really lies
The debate on sovereignty focuses on models. Yet the model is the most easily replaceable layer in the entire stack: one API in, one API out. What actually becomes entrenched after two years of AI operation lies elsewhere.
| Layer | Function | European options | Can US models be integrated? | Lock-in risk |
|---|---|---|---|---|
| Models | Text, image, reasoning | Mistral Large 3, FLUX.2 | Interchangeable via API | Low |
| User interface | Chat, assistants, knowledge access for the team | Long dock | Yes, routed behind it | Medium |
| Orchestration | Workflows, agents, integrations | n8n, Make | yes, as a node in the workflow | high |
| Memory & Data | Prompts, RAG corpus, evaluation sets | own database, e.g. pgvector on Hetzner | model-independent | very high |
The table gets more awkward the further down you go. You can change a model via configuration. You can change a user interface, but that requires training effort. But workflows that have evolved over the years within a closed SaaSecosystem, with scattered prompts across twenty tools and embeddings in a vendor database with no export path: This will take you months, or in the worst case, quarters.
That is why a serious sovereignty strategy starts with orchestration and memory; the model comes last. It is in these two layers that it is decided whether GPT is a guest in your organisation or a load-bearing wall.
The European AI stack in practice: n8n, Langdock, Make, FLUX
The argument that ‘there are no European alternatives’ was valid in 2023. Today, it is merely a matter of convenience. For every layer apart from the absolute cutting-edge model, there are European AI tools that people choose because they do the job well.
Orchestration: n8n from Berlin. When, in May 2026, SAP came on board at a valuation of 5.2 billion dollars, it was the long-awaited confirmation of a principle that has made all the difference to you right from the start: n8n is Fair-Code, runs self-hosted on your server, and every workflow is stored on your end as exportable JSON. A docker compose up, and the orchestration is yours, complete with update control and a full execution history. The model is just one node among many. Claude today, Mistral tomorrow – the workflow remains the same.
Those who prefer clicking to hosting will be well served by Make from Prague – part of Munich-based Celonis since 2020 – with an EU hosting option. Our stance on this is clear: control and self-hosting are arguments in favour of n8n, whilst maximum accessibility for specialist departments is an argument in favour of Make. We show you how to use these to automate processes in your day-to-day business in the n8n guide for SMEs.
Work interface: Langdock from Berlin. A single login for your team, giving access to the leading models from OpenAI, Anthropic and Google right through to Mistral, with EU hosting, ISO 27001 and SOC 2. Crucially, this means that model selection becomes an admin setting. Ideally, your team won’t even notice the switch from GPT to Mistral.
Models: interchangeable, and increasingly European too. Mistral from Paris has found ASML as the lead investor in its €1.7 billion funding round on its own continent and, with Mistral Large 3, a flagship product licensed under Apache 2.0, which you are permitted to operate entirely on your own in an emergency. When it comes to images, Black Forest Labs from Freiburg delivers with FLUX.2 is one of the world’s leading models, built by the team behind Stable Diffusion and valued at 3.25 billion dollars since December 2025. Bringing image generation to Europe no longer comes at the expense of quality.
Underlying this is the question of infrastructure, and that’s the simplest one: Hetzner, IONOS or STACKIT host your n8n server and your databases outside the scope of the CLOUD Act. We’ve described how to run such a stack without a DevOps team in the Coolify Guide.
You have to test failover in minutes
Every provider tells you that you’re not locked in. Don’t believe a single one of them. Interchangeability is a test result, and if you’ve never practised switching providers, you don’t have a choice – you’re just bound by a contract.
Technically, the pattern is unspectacular. Firstly: Centralise model access. In n8n, this means a central LLM component (sub-workflow or shared credentials) instead of thirty scattered model nodes, all of which have to be migrated individually. Secondly: the model becomes configuration rather than code. Self-hosted n8n reads environment variables directly within the workflow:
# Centralised model selection for all workflows
LLM_PROVIDER=anthropic
LLM_MODEL=claude-sonnet-4-5
# Secondary provider, accessed via the error branch of the central LLM building block
LLM_FALLBACK=mistral-large-latestThe model node will then no longer contain claude-sonnet-4-5, but {{ $env.LLM_MODEL }}. That’s the whole trick. It takes five minutes of discipline when setting up a new workflow, but saves you a whole quarterly project in the event of a forced change.
Thirdly, and this is something almost everyone leaves out: a golden set. Thirty to fifty real-world cases from your processes, with expected outcomes, stored as a test run. After every model change, the set runs through once and shows you whether the new model solves your tasks.
These three building blocks form the failover drill: once a quarter, you switch over to the secondary provider on a trial basis and run the Golden Set. The aim is for the switchover itself to take a matter of minutes and for the entire drill, including testing, to be completed in under an hour. The first time round, you’ll encounter surprises – and rarely where you expect them: the secondary model rounds numbers differently, crashes when encountering an unusual date format, calls tools in a different order, or returns JSON with a structure your parser isn’t expecting. That’s what the drill is for.
Prompts, memories, evals: your actual AI IP
After two years of productive AI use, your most valuable asset isn’t your model subscription. It’s what has emerged around it: the prompt library that encodes your tone and your processes. The RAG corpus drawn from your product data and documentation. Your agents’ memories. The Golden Set from the last section. This is process knowledge in machine-readable form – in other words, IP.
The awkward question: who actually owns it, in practical terms? In many companies, custom assistants, threads and ‘memories’ are scattered across employees’ personal chat accounts and the storage systems of a US provider. Formally, the content belongs to you. In practice, however, it’s lost when you switch providers or is a pain to export – and it is precisely this friction that forms the business model.
The self-sufficient approach is unglamorous: prompts are versioned in Git, just like code. Knowledge is stored in your own vector database, such as pgvector on a Hetzner server. You store agent memories in your own Postgres database rather than in a vendor’s in-memory function. Recalculating embeddings when you switch models has become inexpensive. Rebuilding the corpus because it’s stuck in a terminated account will cost you months.
The model is a commodity. Your context is not.
What the legal situation means for your setup
If all this sounds too cautious to you, it’s worth taking a look at the broader legal landscape on which your AI setup is currently based.
Transatlantic data transfers are governed by the EU–US Data Privacy Framework, the third attempt following Safe Harbour and Privacy Shield. The first two were struck down by the European Court of Justice. The third is currently in force but is once again under scrutiny: The EU Court has dismissed MEP Latombe’s complaint in September 2025, the appeal before the ECJ is still pending and the outcome remains uncertain. Anyone who designs their AI processing in such a way that it is only lawful with a valid adequacy decision faces a foreseeable concentrated risk.
Even OpenAI’s EU data residency offerings and the availability of Claude in Frankfurt-based AWS regions do not fundamentally change this: they relocate data, not the parent company.
Added to this is the EU AI Act, whose roadmap was finalised by the Digital Omnibus in June 2026: the transparency obligations take effect from August 2026, whilst the high-risk obligations for autonomous systems do not apply until December 2027. What this means for you in concrete terms, we have broken down in the article on the EU AI Act for SMEs. As for the architectural question, one sentence suffices: The deadlines are shifting, but the direction remains the same.
And policymakers are stepping up the pressure: on 3 June 2026, the European Commission presented its tech sovereignty package, including the Cloud and AI Development Act, with the aim of at least tripling European data centre capacity within five to seven years and classifying cloud services into levels of sovereignty. You don’t have to applaud every initiative from Brussels to recognise the trend.
The roadmap: four steps to a sovereign AI setup
The transformation is a question of sequence, and the realistic unit of progress is one focused project per phase. Four steps:
- Inventory. One or two workshops: Which processes are currently tied to which model, which tool, which account? The list of chat subscriptions, browser extensions and API keys that have accumulated incidentally is usually longer than expected. The key question is uncomfortably specific: what will break if your US provider doubles its prices tomorrow, restricts access or the European Court of Justice overturns the data transfer ruling?
- Adopt a European approach to orchestration. From now on, new automations are created on n8n or Make instead of in closed ecosystems. Migrate existing workflows according to priority, starting with the critical ones. From this point on, every model is simply a node.
- Bring the memory layer in-house. Set up a prompt repository, a vector database on European infrastructure, and export the artefacts from the vendor accounts. This is the step that requires the most effort and yields the greatest gain in autonomy.
- Establish Drill. Build a golden set, configure secondary providers, switch over quarterly and measure performance. Only this step turns the architecture into a robust commitment.
As a n8n agency, we build this layer every day: orchestration, model abstraction and a memory infrastructure that belongs to you. If you’d like to know beforehand where your setup stands today, that’s a case for our AI consultancy.
FAQ on digital sovereignty in AI
Is it GDPR-compliant to use GPT or Claude in a business?
With a Data Processing Agreement, EU data residency and a robust access control policy, the use of these tools can be structured in a legally sound manner; OpenAI offers EU residency, whilst Claude runs via AWS and Google Cloud’s EU regions. The CLOUD Act remains unaffected by this, as it applies to the USparent company. That is why particularly sensitive data should be kept in layers that you control yourself.
Are European AI models worse than GPT and Claude?
The gap has narrowed significantly. Mistral Large 3 is one of the most powerful open-source models, whilst FLUX.2 is a frontrunner in image generation. For most business processes, it is not the final benchmark percentage that matters anyway, but rather integration, costs and data flow. With a modular architecture, you can choose the most suitable model for each task.
What does switching to a sovereign AI stack cost?
Less than a replatforming, because you proceed layer by layer. A self-hosted n8n running on European infrastructure costs a double-digit monthly amount in server fees; the real work lies in migrating the workflows and the data layer. What’s really expensive is the opposite: a forced switch without preparation.
Sovereignty is when the change is boring
Back to the beginning: sovereignty is not a question of flags. A company that uses GPT and can switch to Mistral in a matter of minutes is sovereign. A company that uses a European tool from which it can no longer escape is not. An EU label on a lock-in remains a lock-in.
The real point of European AI platforms is their design principle: open enough that you could leave. That makes staying a free choice. Judge every component of your stack against this standard, regardless of which country it comes from.