← Back to Podcast/How Much Sovereignty Do You Need? Sovereign Cloud, EU Regulations & the Cost of Control
Episode Transcript

How Much Sovereignty Do You Need? Sovereign Cloud, EU Regulations & the Cost of Control

Send us Fan Mail


How sovereign does your cloud actually need to be?

In this episode of DevOps Sauna, Pinja Kujala and Kalle Sirkesalo unpack the different levels of digital sovereignty, from basic EU data residency and access control to operational independence, jurisdictional immunity, and fully air-gapped infrastructure.

They explore how GDPR, NIS2, DORA, the EU AI Act, and other European regulations are changing cloud strategies, why greater sovereignty comes with significant costs and trade-offs, and how organizations can decide what level of control they genuinely need.

If you're navigating cloud compliance, regulated industries, data sovereignty, or the growing tension between innovation and digital independence, this episode offers a practical framework for thinking about where to draw the line.



[Kalle] (0:03 - 0:08)

How do we do software development in the age of AI? What are the AI systems that we use?


[Pinja] (0:11 - 1:15)

Welcome to the DevOps Sauna, the podcast where we deep dive into the world of DevOps, platform engineering, security, and more as we explore the future of development. Join us as we dive into the heart of DevOps, one story at a time. Whether you're a seasoned practitioner or only starting your DevOps journey, we're happy to welcome you into the DevOps Sauna.


Hello and welcome back to the DevOps Sauna. Today we're talking about something that we see our customers talking and asking a lot of questions about. We see this online in the industry discussion.


So let's talk about Sovereign Cloud. And not so much why we should be doing it, but it's more about what is the level of control that is actually needed over the digital environment. There are different levels of requirements at the moment going on, so there must be different levels of control that is needed over the environment.


So I'm not here to discuss this alone today, but I'm joined by our Field CTO Kalle Sirkesalo. Hey Kalle.


[Kalle] (1:16 - 1:27)

Hello. Yeah. So here today to talk about all the regulations and the fun things due to the background on having been working with all kinds of regulated customers for the last 12 years here in Eficode.


[Pinja] (1:27 - 2:14)

Yeah. And this, the question of Sovereign Cloud is really topical at the moment. If we think about the EU regulations right now, not just regulations, but directives, what is the regulative environment at the moment?


So many people are very familiar with GDPR, but if we go beyond that, we have in the past years, we have also gotten NIS2, which has been in force since October, 2024. DORA since January last year. We have the EU AI Act.


There has been a phased implementation since last year. The latest ones being the EU Data Act and EU Cyber Resilience Act, which is not fully enforced yet, but all of these are imposing requirements on companies and how they act with their digital environment. What are the questions regarding these requirements at the moment that we get?


[Kalle] (2:14 - 3:54)

Yeah. So most of the time we don't get the requirement as this regulation, what happens here? Because we are not a legal house.


We get the question, Hey, we got hit by NIS2. Can you help us with this? And then it creates this discussion that like, okay, how do we help you?


Because as we talk pre-show here, these are not regulations most of the time, these are directives. And that means that the regulating party is actually the country where you reside, which means that in many of our customers that are bigger companies, it ends up being 20 different regulations that come into play because it's 20 different laws. So because it's a directive, every European country defines it separately into their law, how it works.


So this creates these funny things where we can see a critical infrastructure provider, somewhere like Finland going full in on cloud and on the other side, having on, let's say Swedish or a Danish company, as an example, being said that you go on-premise back because we don't trust the public cloud. And these are both true at the same time, because it depends on which law, which country's law abiding things are you following. You can get a lot of it sorted by having a really, really good policy management and system management, because then you know which systems are that critical infrastructure or comparable.


And you just work down that part of the company. But the challenge becomes when your whole company is built around regulated industry and these things start to attack you or defend you, depending on things. Because like it all started from the fact that the European Union wanted to protect people, us.


And the nice thing with GDPR was that when we came out, every one of us was in chaos, like, how are we going to do this? What's going on? And reality is it was just one more error that we had to say, yes, yes, I'm fine on my data going to the USA.


[Pinja] (3:54 - 4:22)

For us as individuals, the visible change was not that big, but this is something we have lived with for many years now with GDPR and NIS2, DORA, EU AI Act, they're coming into force now. But there are, of course, incentives for companies, like number one, if you're in a regulated industry, you don't want your things to get out. But there are the fines, for example, like NIS2, there's the max fine.


Is it either 10 million euros or 2% of your annual revenue?


[Kalle] (4:22 - 6:51)

I think that's the minimum, actually. I think that's the minimum. So the big thing is that like GDPR is where the European Union started to learn.


So we learned that it doesn't really matter if we just tell them to put a legal thing in place. So if you start looking at NIS2, DORA, EUAI Act, EU Data Act, and EUCRA especially, it starts to have enforcement things in there. So you need to have, for example, in EUCRA, you have to have a software bill of material, which there is an episode in our system, and you have to follow it and you have to control it.


And he's become a thing that the EU has started to put there. So that means that when you start looking at these different acts, and this is how we get to the sovereign cloud versus regular cloud versus security, we start to get into this discussion that like, okay, these different acts, how do they get counted on your specific field and your specific thing? So what are we thinking that like, okay, what is the level that the sovereignty do we need?


So how much is, in our case, visit in Finland, Finland specific, what's Sweden specific, what's Denmark, Germany, UK specific, versus what is European Union specific, and what is trusted partners specific. So that would have the USA in it. So basically NATO level, and what is then limited on something else, right?


Because we have these tiers, and we have to look at it from the eyeglasses of when do we go to real sovereignty, that this needs to be within Finland, and when do we need to be in, okay, the region is fine. And when do we go in, yeah, but it's actually fine as long as we tell that, hey, we sent the data to the USA. And this creates this differentiation that we use sovereign cloud on everything in this, like, in the worst case.


So we have systems like Microsoft's sovereign cloud, which then in France, they go into the court, and they say that, yeah, the US staff can't get access to it, because we are an American company. And you're like, that's not a sovereign cloud, because they can get access to it. But from Microsoft's point of view, it is a sovereign cloud, because most of the actions are happening within that sovereignty, and all of the support staff, etc, that you see as a customer are that, and to do the fact that they need to break their own prerequisites, but you don't know that they broke them, because there is no control over this, you can't follow it, because they are an American company, like, of course, their CEO can command people to do things. So this is the challenge when we talk about this, that like, this is the challenge, like, how sovereign is Amazon's sovereign cloud that they just released?


What level do we think about?


[Pinja] (6:51 - 7:08)

Yeah, there is, as you say, the access rights, there is thinking about ownership of the data, ownership of the, and operationality of the infrastructure, like, as many levels that where we can consider the sovereignty of, for example, now, Amazon's Amazon's cloud, sovereign cloud.


[Kalle] (7:08 - 7:45)

Yeah. And then the whole thing, like, we have this thing called Azure Entra, as an example, all our access data is being managed by that in most companies, because it's so simple. Well, now we have an American cloud in this mix.


So do we swap that also? Like, where do we draw the lines? Like, what data is allowed to go outside?


And what do we do? So this starts building this, we call it sovereignty maturity model in Eficode, where we think about, like, what are the levels of sovereignty that you're looking for? And we're kind of thinking from the point of view of creating five levels.


And I said, I joked to Pinja that there is a hidden sixth layer. Let's see if we get there.


[Pinja] (7:45 - 8:12)

Yeah. So let's talk about the maturity framework a little bit. So like, I don't think we can recommend anybody to go level five if they don't really need to, because there are costs, it is not just a simple thing to go fully sovereign.


But the typical levels, like the first level that we have identified here, is just a data residency to meet GDPR regulation requirements. The EU region is selected, it is just a, this is a very standard way to do it, right?


[Kalle] (8:13 - 8:54)

And anybody in the USA, if you're listening to this, most of this doesn't relate to you, you guys, you guys need to do your own thing. So we're talking from the European Union point of view, because the European Union has been having this discussion for the last probably 10 years, in reality, but last year in honest discussions. And as I said, the levels go from one to five, and one being the easiest, five being the hard.


And I like to say that it's exponentially more expensive to go down the layers. So that means that going to the fifth layer from level one means that you're spending billions on a data center. So you will have your own data center.


Level one is you still have Amazon, Azure, and so on, and you just set the region to your own region that covers most of the time GDPR.


[Pinja] (8:54 - 9:09)

It's very simple. That's what many, many companies are doing when you need to fulfill GDPR regulations. And like even if you are a US company, but if you have operations based in the European Union, you need to oblige to these requirements as well.


[Kalle] (9:09 - 10:23)

Exactly. And then we start implementing the AI Act. So the latest data set of data things that are coming, but what if the past is coming into play?


So things like you probably noticed like AI can't make decisions on your equipment policies. It doesn't mean AI can't be in your equipment system. It just can't make the decisions.


We might have a different episode of AI Act in future, but like, I'm not going to go into detail how that works. Again, we're not a legal house. We're here to talk about how you build systems around these ads.


And the key thing here is you still need to follow GDPR. And do you remember, you always have to do the previous levels. So this is level two, it's access control.


So you need to manage your own keys. So your data is no longer allowed to be managed like somebody else's key. So it means that you have to select that this data is being decrypted.


And that means that now someone else can get access to this data, but you know, if they got access to it by the logs of that system. Of course, if you're storing the log key in the same system by the same provider, as we saw in the Microsoft leaks, they probably have access to it without you knowing, but officially they are not supposed to have and officially they're not supposed to do. But we keep finding these kinds of security holes because of engineering mistakes that we've made.


[Pinja] (10:24 - 10:34)

So this is basically us going from residency to actually being more controlled. With the first level, with data residency, we only use setting change, right?


[Kalle] (10:34 - 11:21)

Yeah. So this is basically us moving from we change the region to be data is around here to A, we actually know who accesses this data, that the people accessing it are EU residing. So we know that the people working there are within the EU and we are lockboxing the data behind approval.


So we have an approval process of getting access to those data systems that are critical within the AI Act and GDPR. So for example, again, we're trying to prevent that HR system from leaking and being used for AI training, for example, or comparables. So we're trying to create these realistic ways of showing this is a controlled environment.


This is not some kind of a damaging environment. So then from level two, level two is still really easy to do in cloud. Like you can do this in an Atlassian cloud.


Yeah.


[Pinja] (11:21 - 11:33)

We're still talking about very typical levels of basically access control, but then we're crossing the line towards DORA and NIS2. And those do not apply to every single company, do they?


[Kalle] (11:33 - 11:57)

Yeah. So GDPR follows every single company in the EU. The AI Act is for most companies in the EU, to be honest.


There are, I think it's not all, but like you will end up hitting it most of the time hitting it if you're listening to our podcast. That's the honest thing. Like if you're listening to this podcast, most likely you're going to get hit by most of AI Act and EU CRM.


[Pinja] (11:57 - 11:58)

Yes, correct.


[Kalle] (11:58 - 12:52)

And GDPR. Like if you're listening to this, if you're outside of these, please send us a message. We love to hear from you.


But based on what I've seen, the statistics, it's mostly Europeans listening to this podcast in regulated fields. So basically now we start hitting the line of you becoming a recreational industry. So this is when you would get invited by our sales guys to calls with us, for example, because we work with recreational industries.


This is when we start caring about your problems way more, because this is when you're starting to have real challenges. So this is when we start seeing the four acronyms like DORA and NIS2 coming into play. We start seeing all kinds of funky stuff coming into play.


And you start having your own compliance and security people that are really annoyed by most of the stuff that you do. And that's just because they have so many controls in place. So this is where you start seeing ISO 27001 being like the basic requirement to even be in the business.


[Pinja] (12:52 - 13:05)

So this is not just control, but it is actually towards operational independence. And do bear in mind, this is only our level three that we've identified. And we're already talking about operational independence here.


[Kalle] (13:05 - 14:33)

So this is when you still can use cloud most of the time in these environments, but now you have to do the access control. So encrypt everything. You have to get the logs out.


You have to know that the entity is being covered in the European Union. So you have to have a tracking that this is made to be operated in the European Union. So like, for example, GitHub Proxima is one that they named it before, but it's nowadays called Data Residency.


GitHub Data Residency would be within this still. It's not going to be the next one, basically, but you can just and just get it through this one by getting every single tick box ticked. You have to have an independent control plane.


So it has to be separate from others. It can't be a single place that everybody can access. And you have to have an exit strategy.


But the exit strategy, the one guess we have seen is your exit strategy for Azure is AWS. From AWS, it's Google. And then Google, it's Azure.


So circular financing is not just AI, it's also an exit strategy. But again, that is accepted by some organizations, some countries, and depends on the country's definitions. So this is when we start seeing these two coming to play heavily.


And these two have different levels. If you happen to hit these two plus critical infrastructure providing and with the data being critical, you start having level four. And level four is to say goodbye to Microsoft, Google, and AWS on all of the data.


[Pinja] (14:33 - 14:47)

Yeah, because we're now talking about jurisdictionally immune level here. So, okay, three, operational independence. And now we talk about jurisdictional independence.


And going without all those providers you listed, is it going to get really hard?


[Kalle] (14:47 - 16:56)

Yeah, it's getting to the level where I start asking the customers, are you really wanting to be there? Like in level three, you can still build stuff around it. Like you can still build something in the cloud providers in very limited capacity.


But then like when you go to level two, it becomes like in level three, theoretically, most stuff can't go to level three. So that's when you start being like, okay, you're a cloud, we can't put stuff into operational sovereignty into your cloud. But most of the data going to your cloud or confluence wouldn't be the operational sovereignty level.


But when you start hitting jurisdictionally immune, and it needs to be prosecutable in the European Union, or preferably in your country, you start having no US parent companies, you need to have like, you have to be able to extract people, you have to be able to show this is the system that is running, we have to have like all kinds of European headquarters that we can inform and track. So this is when you really can't have any Atlassian cloud anymore. And we start having these critical systems.


Again, if you're doing a web page, you can still do everything in cloud still, as long as your system says that's not regulated. If you're doing, let's say, for example, in Finland, you would do the gun control system, that would be level three, minimum level four, most likely, if not level five, we'll get to level five, usually it would be level four. So level four starts to force us to actually start talking about how we actually do these things, so that we are within the European Union.


Theoretically, level three is we have seen some of the systems being allowed into the US clouds, but so that they're fully managed, and there is an European region and so on. But the reality is that level four is where that no longer exists at all. And we start seeing European cloud providers becoming a discussion.


So this is where UpClouds and Hetzners and whatever OVH and so on become the providers. Because I was going to go to level five, which is to buy your own data center. So that's the simplest way to understand it.


It's called fully sovereign, but it means that we cut the internet cord, we make it so that you have to work in a bunker at a specific location. So this is when we start talking about defense manufacturing or the defense sector.


[Pinja] (16:56 - 17:15)

Because this is, as you say, we have no internet connection. This is totally air gapped. We're really talking about the small fraction of industries and companies operating on this level.


And as you can hear, from what Kalle just you described, that this is not just a small thing to go to this level.


[Kalle] (17:15 - 18:23)

Now, Azure DevOps, for example, no longer goes through anything. It didn't go through to level four, by the way, but it doesn't. This is where it's like completely gone.


You can get the Azure DevOps server and install that on your data center if you want. But the reality is that most of the time, this is where we start talking about when do we buy NVIDIA GPUs. And you start thinking, well, we can't buy any because it's sold out for three years.


And then we're like, well, you can actually because it's just sold out from NVIDIA. But anyway, level five is basically, if you can avoid it, you never go there. So air gap usually is separated even within those companies.


But when I say defense field, usually defense has level three, level four and level five, it's the same organization separated by some policy management. Because running everything at level five means that your company would do it approximately the correct day and your innovation speed would collapse because you can't really do anything with the current technologies. You want to run your innovations on level three, preferably level two if you can, so that you can really keep the speed, have AI, for example in use, have different things that don't require your investments on.


And then you want to bring it down that level when you start going operational and functioning and working.


[Pinja] (18:24 - 18:58)

So the whole organization doesn't need to be behind that air gap line and area. Yeah. So this is because we went from obviously four being actually being jurisdictionally independent.


And now we're completely technologically independent as well. So it is really costly because if we think about why would somebody go five, you mentioned a couple of things like the military defense industry, but not even all, whole of those companies need to go level five because there are so many trade offs that you need to consider the cost of being one of them. If you need to build your own data center around this.


[Kalle] (18:58 - 20:45)

Yeah. So it's basically like it's very specific things that you want to put on level five, if you can avoid going fully in it. So it's again, our goal is usually to try and figure out where to put most of your systems?


How do we move between these? If we ever move and how do we avoid these things? Cause like you don't want to be in level five with everything.


Anybody who has tried to host an email server themselves knows how much of a pain that is. So if you can put it on level two, that email never has anything that would go below level two, you can feel really secure. So why did I say that level six exists because when you have a fully sovereign crowd, you're still tied to the USA and Taiwan at the moment, because all of the semiconductors come from those things.


So level six, theoratically, I think we would be what China is building where they can manufacture everything themselves, even the CPUs, allowing them to go deeper than it was fully sovereign into fully independent. Cause at the moment, if we take those data centers into a level five, we still buy everything that we maintain those things from countries that are not within European Union, let alone like within ourselves, because fully sovereign usually means stay in Finland, for example, with Finnish staff or Finnish security clearance or UK security clearance. So we started reducing even the working pool from European sovereigns.


So usually what I like to say is you want to stay in level three and four, so you can use European staff. Level five is where you need to hire that country specific staff into that specific bunker with that specific set of salary that they want to work in your random location, because they can't work from home. There is no working from home if there is no internet in the system.


So level four and three still allow you the internet. Level five no longer does that.


[Pinja] (20:46 - 21:24)

Yes. So there's so many trade-offs. And like, if we consider that, what is the price of going sovereign?


And like, if we really wanted to have full sovereignty, but even when you go down deeper to those deeper levels of sovereignty, like costs being one of them, there needs to be the decision, like, are we ready to reduce our service catalog because of this decision? Are we ready to have slower access to a new cloud and AI capabilities? Operational complexity goes way up.


And of course, the organization is not exactly able to scale their business as fast as possible, as fast as before.


[Kalle] (21:25 - 23:16)

Yeah. So basically we can forget all the cloud functions. So if we go and look at the cloud competitors of the European cloud, they are maybe 10, 15% there with the offering compared to the major clouds.


Serverless, you can build it on top of those, but it's not really serverless. You can build it by having a multitude of providers in that one cloud. We can bring Aiven, for example, and UpCloud together, and we have Aiven do the databases and we have UpCloud doing the infrastructure.


But that's not like we click in a UI and we get everything sorted out in one go, like it was in the, like it is in Amazon or Azure or comparable. So it becomes this thing where all of the latest functionality that the American cloud giants earned billions on these systems, so that they can put those billions into GPUs at the moment, that means like we are losing out on all of that if we're in the level five. We are starting to lose that already on level four.


So it becomes this game where we are getting left behind every day because we don't invest in that. So it becomes this cat and mouse game where we need to figure out how do we actually get, for example, proper European cloud or proper, like at least within Finland, for example, a Finnish cloud for all the Finnish big companies that would need to be here. But we are not there.


We don't have such policies or centralized locations because we've been kind of living in a trust across the globalization era. We've been very much into globalization here, which we've taken as the price of losing sovereignty in history, because we've gotten way cheaper goods, we've gotten way faster development, and we haven't had to invest in the public cloud investment side. And now we're starting to see that cost us, and we're starting to see investments in this area.


And it's like, at the same time, we're seeing the public cloud vendors investing heavily in here to build data centers and get GPUs because we have a really good infrastructure in Europe, except Germany. But Germany is working on it. Germany is going to be there in a few years.


They're working on it.


[Pinja] (23:16 - 23:57)

Yeah, there are changes coming. We will see a fully European cloud at some point, that's for sure. But like, for example, if we think of the big providers, like, let's think about Atlassian services, how many of the companies are actually running Atlassian aservices right now.


And we're not that far away from actually Atlassian having their data center end of life. So we're only talking about two and a half years, a little bit over two and a half years, so March 2029, I think, on that as well. So some organizations that might be actually on those higher levels still, but you need to consider that you still want to run your stuff in data centers.


Some data centers are actually going to go end of life soon.


[Kalle] (23:58 - 26:03)

Yeah. So the problem is, this is what we are talking with customers a lot at the moment, is the data that you put into Atlassian, level four or five. And we aim to get classifications above that when possible, so that we could put them in cloud.


Because if you don't put it in cloud, it's just on top of the price of sovereignty becomes our closest appeal for Atlassian, it no longer works. We can't do it that way on new tools. If you go to GitLab, it's not the same experience.


It's not intended to be the same experience. If you go to what any of other tools that we've like thought about to replace Atlassian, it's a completely different system. So if you would go into something like Open Project or NextCloud or Blue Spice, or what other tools are there, like Keycloak for access management, none of these work the same way.


It's not like a single button works now. It has maintenance costs. So you used to have to, as a company, take the maintenance costs on yourself, because these are not cloud products in the cloud, or you need to buy managed services, like what we've been doing for customers for 12 years.


And that creates this whole thing. How do we actually get these different things into a level that is either A, we accept that we're going to lose functionality and change our process and ways of working, which we have to do anyway, because of AI, but we want to keep pushing that ball forward, right? Like we always, so how do we keep that ball still like in the hands of us for a moment still? So how do we classify these?


Like are these systems really that? Do we need to put them in level four and five? If we do, how do we do that?


Is our source code really secret? Or is that public? Or like, is that confidential?


What level do we put it? And this becomes this game of like, what are the risks of us losing our source code, for example? Is that the secret source of our system?


Or is that actually just like one of those things that we shouldn't actually be caring about? That's not the business thing that we're doing. And then these are the questions that people are asking at the moment in these heavier accredited industries, because they need to have an answer.


Do we go to Atlassian Cloud? Or do we go to GitHub, for example? Do we go to like, how do we do software development in the age of AI?


Like what are the AI systems that we use?


[Pinja] (26:04 - 26:27)

And not to go overboard with the requirements and way too deep into the levels that are not necessary for them to go into it. This is something I think Kalle, you and I could discuss for another two, three episodes as well. I know that we didn't even get to discuss how AI impacts this.


Because I think I want to save that for another day. But I think that's all the time we have for today. So thank you, Kalle, for joining me in this discussion.


[Kalle] (26:28 - 26:29)

Thank you for inviting me.


[Pinja] (26:29 - 26:40)

And thanks, everybody, for tuning in, and we'll see you in the Sauna next time. We'll now tell you a little bit about who we are.


[Kalle] (26:40 - 27:06)

Hello, my name is Kalle Sirkesalo. I work as a Field CTO in Eficode at the moment. I've been here for over a decade, and I'm at the moment mainly focused on AI-powered tooling, especially in the SDLC pipelines.


I'm building very stable platform engineering platforms and DevSecOps practices. And my biggest job is scaling CI/CD and SDLC in industrial and regulated industries.


[Pinja] (27:07 - 27:22)

I'm Pinja Kujala. I specialize in agile and portfolio management topics at Eficode. Thanks for tuning in.


We'll catch you next time. And remember, if you like what you hear, please like, rate, and subscribe on your favorite podcast platform. It means the world to us.



This transcript was automatically generated by the podcast creator and may contain errors. Aggregated via the PodcastIndex API.