
A case study
The quarterly Supervisory Board meeting goes according to plan. The Executive Board has prepared thoroughly: strategy, figures and outlook are all in order. Then, during the coffee break, a member of the Supervisory Board approaches him. Casually, between two conversations. He says he’s read some worrying things recently – about digital dependencies, data access and geopolitical risks that don’t show up in the balance sheet figures. After all, the company does have contracts for cloud solutions. Could this be added to the agenda for the next meeting?
The CEO naturally agrees. On his way back to his office, he begins to ponder: what would he actually say in reply?
The world has changed—but some contracts haven’t
Since 2018, the U.S. CLOUD Act has established a legal framework that, under certain conditions, allows U.S. authorities to access data held by U.S. companies—regardless of its physical location.
The major hyperscalers have responded with contractual safeguards, technical isolation measures, and European sovereign cloud offerings featuring specially designed operating models. This reduces the risk but does not eliminate the legal framework.
What executive and supervisory board members must therefore understand and evaluate is the difference between what a provider contractually guarantees and what remains legally possible. This assessment is precisely what constitutes a genuine leadership task.
Added to this is a geopolitical dynamic that was still considered unlikely several years ago. Anyone who signs a hyperscaler contract for critical banking processes today is also implicitly entering into a contract regarding jurisdiction and data access—the consequences of which are rarely listed on the first page of the proposal and even more rarely discussed by the executive board or supervisory board.
Anyone who signs a hyperscaler contract today is also implicitly entering into an agreement regarding jurisdiction—and this part is rarely mentioned on the first page of the proposal.
Susanne KochwagnerDirector | Cloud Transformation | msg for banking
AI exacerbates the problem because it makes it invisible
Generative AI has created a new dimension of dependency that is not yet systematically accounted for in traditional cloud risk analyses. When an institution uses AI models from an external provider for credit decisions, fraud detection, or customer communication, it is outsourcing not only computing capacity but also decision-making logic. And that is a fundamental difference.
To the questions:
- Which model processes the request?
- Where is the input data temporarily stored?
- Is customer data used in the model’s training, and if so, on what legal basis?
there are not always satisfactory answers today: not because providers refuse to provide them, but because these questions have not yet been asked—or have not been asked clearly enough—at most institutions.
Digital sovereignty in the age of AI therefore means, first and foremost, understanding which decisions the institution still makes on its own and which it has delegated to models whose functioning and training basis it does not fully understand or have insight into.
DORA (Articles 28, 30) and the EBA guidelines on outsourcing (EBA/GL/2019/02) require financial institutions to be able to fully identify and control their third-party ICT service providers, including sub-outsourcing chains. AI models, as outsourced decision-making components, fall within this scope—even if they are not currently classified as such in all institutions.
For legal review: Does this also apply to API access to external large language models (LLMs) without a formal outsourcing agreement? The answer has direct implications for the contractual documentation.
What this means in practice for executive and supervisory boards
Digital sovereignty is not an IT issue that can be delegated to the CIO. Ultimately, it is always a governance issue: Who decides which processes will be outsourced? Who approves the jurisdiction under which customer data is processed? Who verifies that the ability to exit and audit access are actually contractually guaranteed—and not just mentioned in the proposal?
Today, these decisions are often made—unnoticed—within technology and procurement processes, and their consequences only become apparent during supervisory board meetings, BaFin audits, or crisis situations.
There are three questions every executive board member should be able to answer without first having to call the CIO:
- Which of our critical processes are hosted by providers subject to U.S. law?
- Do we have contractually guaranteed audit access and a documented exit strategy for these processes?
- Who in our organization is responsible for these issues and reports on them regularly to the board?
These three questions sound simpler than they actually are. And for each one, there are good and correct answers. Having a clear answer to all of them does not necessarily mean you’re fully in control in every respect—but not having any answers certainly does not.
The first step here isn’t necessarily a completely new strategy. And it certainly isn’t frantic activity. Rather, it’s an honest assessment: Which cloud-related contracts are in place with which providers under which jurisdiction? And who within the organization has an overview of this?
Institutions that have already established this transparency for themselves regularly find that the picture is more fragmented than expected—and that the primary need for action lies precisely in creating transparency, not in deploying new technology.
Any executive board member who honestly answers these three questions is doing more than just preparing answers for the next supervisory board meeting. They gain a framework for action that makes a difference: externally toward the supervisory board, and internally within their own organization. Because digital sovereignty cannot be achieved by simply checking off items on a checklist; it must be developed dimension by dimension. And that’s what makes the difference.
Digital sovereignty is not a state that can be described as simply “yes” or “no.” It is a decision-making framework—and those who are unfamiliar with it end up delegating strategic control without even realizing it.
Susanne KochwagnerDirector | Cloud Transformation | msg for banking
What this series is about
This series is designed to build decision-making capacity among CIOs and COOs, executive boards, supervisory boards, and advisory boards—all of whom are increasingly confronted with this topic without always having the tools to ask the right questions. It will not provide simple answers.
The series explores the various dimensions of digital sovereignty: from the issue of data sovereignty to technical dependencies, operational resilience, and governance.
The goal is always the same: to be able to make informed and, therefore, well-founded decisions.
The next article delves into the first operational dimension: Who really owns a financial institution’s data, and which five key questions can help clarify this?



