Digital Sovereignty Beyond Black and White
Digital sovereignty is often the subject of heated debate. What bothers you about the current tone of the discussion?
Marc Holitscher: The debate often becomes overly simplistic. An environment is considered either completely sovereign or entirely controlled by others. The truth is, there are many shades in between. In our conversations with customers, the focus is on very specific questions. Where is the data stored? Who can access it? Which laws apply? And how can AI be operated securely? Once these questions are addressed systematically, a controversial topic becomes a manageable challenge. That is exactly where we start with our customers.
What are customers most concerned about?
Marc Holitscher: Most often, they want to benefit from the advantages of the public cloud while retaining control over their own data. There are also questions about third party access, resilience, and dependency on individual providers. Another concern is the possibility of losing access to a platform for political reasons. These topics come up in almost every conversation, across industries and organizations of all sizes.
One recurring topic is the US CLOUD Act. Does it give US authorities unrestricted access to Swiss data?
Marc Holitscher: No, that is not an accurate picture. The CLOUD Act is a regulated legal process with clearly defined limits, not a blank check. Our transparency report documents government requests. The figures for Switzerland show that the type of access often described does not reflect what happens in practice. While the CLOUD Act should be considered as a part of a risk assessment, it is not a valid blanket argument against using the cloud.
What happens if the US government prohibits Microsoft from providing services in Europe?
Marc Holitscher: This scenario is frequently raised, and we take it into account. Microsoft has committed to legally challenge government orders that would restrict access to its services. There are also technical answers. Azure Local can be operated in a local environment and gives customers the ability to control their workloads independently of the global cloud infrastructure. Depending on the requirements, the environment can be operated either connected or deliberately isolated.. This means operations do not depend on a single point. Customers retain the ability to act, even in an extreme scenario.
Customers decide where to operate their data, whether in the public cloud, in a private environment within the country, or completely disconnected from the network.
Freedom was one of your key messages at the event. What do you mean by that?
Marc Holitscher: Ultimately, sovereignty means freedom of choice. Customers decide where to operate their data and applications, whether in the public cloud, in a private environment within the country, or completely disconnected from the network. Customers have that freedom of choice today, and that is exactly the point. Strength comes from intelligent connectivity under clearly defined conditions. Our role is to provide the right option for every requirement.
At the event, you presented new controls. What do they mean for customers?
Marc Holitscher: They provide greater control over customers' own encryption keys. With External Key Management, customers manage their encryption themselves and retain full control over their keys. Data Guardian ensures that access is limited to individuals based in Switzerland, with all activity documented in a tamper resistant log. For regulated industries, this kind of demonstrable control is important because it can be verified during an audit.
What role does AI play in these sovereign environments?
Marc Holitscher: AI is significantly changing the requirements for sovereign infrastructure. Many organizations want to run their models close to their data for reasons of control, latency, and traceability. This is where the interaction between Microsoft and local partners becomes particularly important. Azure Local brings cloud capabilities into a controlled environment, while Green provides the Swiss data center foundation. With high power density, powerful GPUs, and infrastructure designed for AI workloads, AI applications can be operated locally without giving up the benefits of modern cloud technologies.
Chris Keller, CRO at Green, and Marc Holitscher, NTO at Microsoft Switzerland
On Sovereignty Day, you presented your collaboration with Green. Why does the choice of data center play such a central role?
Marc Holitscher: In sovereign architectures, it is not only the platform that matters, but also the location where it is operated. You need a data center that provides availability, security, and connectivity in Switzerland. This is where Green comes in. Green provides the Swiss foundation for Azure Local, with four data centers in Switzerland designed for geographic redundancy, Swiss based operations, and Swiss law.
On this foundation, customers can operate Azure Local either connected or isolated, depending on their risk profile and requirements. Organizations already using the public cloud or hybrid environments can complement them with a fully local architecture operated in Switzerland. Private connectivity to Microsoft Azure is provided through Azure ExpressRoute, a dedicated private network connection. This keeps local workloads closely connected to Azure services while the data remains in Switzerland.
Why is the platform alone not enough? Why is an entire ecosystem required?
Marc Holitscher: A robust environment consists of several layers that need to work together. Hardware partners provide certified platforms with server, storage, and networking components. Green provides data centers, including power, cooling, physical security, and round-the-clock operations. An integrator designs the overall solution, handles migration and configuration, and supports the customer through go-live. Connectivity links locations, the data center, and the cloud through secure and redundant connections. It is only through the interplay of these roles that a strategy becomes a resilient architecture.
What advice would you give a CIO facing this decision today?
Marc Holitscher: The process starts with an honest assessment of the current situation. An organization should understand its dependencies and identify which data and processes are critical to its operations. Based on this, a deliberate choice can be made between the available options, ranging from public cloud and hybrid models to fully isolated operations.
The key is to maintain the right balance between security and the ability to innovate. Too much caution slows value creation, while too little control increases risk. Organizations should take a deliberate approach to managing this balance and review it regularly. Together with our Swiss partners, we help them do exactly that.
Ultimately, sovereignty creates one thing above all: the freedom to use modern cloud technologies where they deliver the greatest value, while operating critical workloads on reliable infrastructure in Switzerland where additional control is required and specific regulatory requirements need to be met.