Digital Sovereignty & AI

What would you do if your most important tool doubled its price tomorrow – or simply stopped being available? If the honest answer is "no idea", we are right in the middle of the topic.

For me, digital sovereignty does not mean building everything yourself. It means knowing who holds the key – and being able to hold it yourself when it counts. That is first a question of people and organization: Who understands the dependencies? Who decides? And does the knowledge sit in-house or only with the service provider? How I approach such engagements is described under Process.

"Compliance asks: may I act? Sovereignty asks: can I act? And that is decided by the weakest layer – not the strongest."

— Stephen Kunstmann

Make dependencies visible

First the map, then the route.

Which tools, data and providers carry your day-to-day work – and what happens if one of them disappears? I make this visible together with business and IT, without finger-pointing. Often this overview alone is the most important step.

Decide deliberately

Decide rather than have it decided for you.

Which data belongs where? Where is a large cloud service perfectly fine, and where do you need a European or in-house environment? I help you define criteria that still hold in two years – principles rather than rules.

Competence in-house

Sovereign is whoever understands it themselves.

The best infrastructure is of little use if the knowledge sits only with the provider. I support teams and leaders in understanding digital dependencies and carrying change themselves – including resistance and communication.

The sovereignty chain: four questions

Whether AI, ERP, CRM or backup – I ask these four questions of every externally sourced service.

  • Location: Where is the data physically stored – and where in a failover?
  • Operations: Who accesses it during operations – support, remote maintenance, subcontractors?
  • Jurisdiction: Which legal system can reach the operator?
  • Exit: Can I get my data back out – and keep working afterwards?

If you cannot answer one of them, you know where to start.

Staying able to act when the situation changes

In the German Armed Forces we called it Leben in der Lage – living in the situation. In the digital world it is more relevant than ever.

Prices change, providers get acquired, rules shift – and the EU Data Act and AI Act add new rights and obligations. Being sovereign does not mean predicting every development. It means being able to respond: with a plan B, with people who can read the situation, and with decisions that someone owns.

It is no coincidence that Karlsruhe, close to where I live, is putting the topic front and center. Around the Karlsruhe Manifesto for Digital Sovereignty, the karlsruhe.digital initiative puts it in a nutshell: understand, decide for yourself and stay able to act. That is exactly where I start – with people and within the organization.

AI as part of it

With AI, dependencies currently form fastest – and are most easily overlooked.

Does everyone really need to become a prompt ninja? No. AI should be as easy to use in everyday work as a finished Excel sheet – experts build it, your team uses it. Sovereign here means: you know which model works with which data, and you can swap it when the situation changes. Including the honest question of whether you need AI at all yet.

"AI is not the problem. It is the amplifier."

— Stephen Kunstmann

Strategic Workshops

What does AI actually deliver for you – and what does it not?

C-level workshops on use cases, prioritization, risk, governance and measurable business goals – including which data may go into which model. I start with an expectations check-in: clarify what you need upfront rather than discovering afterwards that we worked on the wrong topic.

Expert-Level Prompting

The prompt stays in the background – like an Excel formula.

Deep prompting capabilities for reliable outcomes in analysis, text, code and assistant workflows. Your domain team uses the template; I make sure it holds up – including quality assurance.

Architecture and Integration

From prototype to workflows that work in daily operations.

Design and implementation using LLM, LRM, foundation models, RAG, MCP, APIs and production-oriented toolchains. Multiple models per use case, flexibly interchangeable – depending on protection needs, from large cloud models to European or self-hosted options.

My AI Stance

Good AI solutions must be easy to use in daily operations, without prompt overload for domain teams. Makes sense, right?

In workshops I rely on pairing: domain experts and technical specialists work together. The domain side owns quality assurance – because AI answers with confidence even when it is wrong. Practical examples are on References.

"AI does the heavy lifting. You keep quality assurance."

— Stephen Kunstmann
  • Lean usage for users without direct prompt interaction
  • Principles rather than rules – otherwise you cannot keep up with AI
  • Not every task needs AI: Is the problem complex enough? Does the effort pay off?
  • Multiple LLMs per use case, flexibly interchangeable – no lock-in to a single model

How I explain AI

An everyday image first, then the technical term – as in my workshops.

Library and cut-off: A language model has a knowledge state with a fixed date – like a library that does not instantly hold every new book. RAG is the index: I pull your files selectively, not everything from memory. PDF vs. Word: Data quality decides whether AI works reliably – poor sources produce poor answers, regardless of prompt quality.

Technology and Tool Experience

I am a practitioner – I build, test and implement, rather than only showing slides.

  • Platforms: Cursor, Anthropic, Gemini, OpenAI/Azure GPT, Mistral, Perplexity
  • Tools: Code Interpreter, image generation and API-based automation
  • Delivery: from fast prototypes to production-ready AI workflows

Which format fits you? See my Services – or we clarify it directly in a call.

Discuss sovereignty and AI in an initial call

Frequently asked questions about sovereignty and AI

The questions that come up in almost every initial call – answered here in advance.

Does digital sovereignty mean dropping every US service?

No. Sovereign means deciding deliberately – and being able to switch when the situation changes. Some data belongs in a European or in-house environment; for other things a large cloud service is perfectly fine. What matters is that you know what sits where, and why.

Isn't digital sovereignty purely an IT topic?

Technology is the smaller part. What decides it is whether people understand what they depend on, whether someone owns the decision and whether the knowledge stays in-house. Without that, even the best infrastructure helps little.

Does my team need to learn prompting now?

No. Just as not everyone needs to build pivot tables to use Excel. The experts build the template, your team uses it. The prompt stays in the background – like the Excel formula.

Which tools and models do you work with?

Cursor, Anthropic, Gemini, OpenAI/Azure GPT, Mistral, Perplexity – the right model for each use case. I deliberately stay flexible: the market moves so fast that a fixed commitment to one model quickly becomes a brake.

How does our own data get into the AI?

Via RAG, APIs and MCP – controlled and traceable. More important than the technology is data quality: poor sources produce poor answers, no matter how good the prompt is.

What if the AI talks nonsense?

It does – and with full confidence. That is why my rule is: AI does the heavy lifting, your domain team keeps quality assurance.

Your question is not covered? Then ask me directly.