Module D4 · Digital Sovereignty · Executive Leaders Track · 2026
Module D4 · Half-day · Executive Leaders Track

Digital
Sovereignty
Executive Briefing

Cloud Act, vendor dependencies, ICT concentration risks

Digital sovereignty is not an abstract geopolitical topic. It is the concrete question of whether your organization will retain access to its data, systems, and capabilities in the event of a crisis, a regulatory shift, or a commercial breakdown with a critical vendor. This module provides the tools to diagnose, prioritize, and decide.

Executive objectives
01Understand why Cloud Act and DORA create a real jurisdictional conflict
02Diagnose your organization across the 9 dimensions of sovereignty
03Prioritize actions on the impact vs effort matrix
04Build a sovereignty roadmap ready for Board presentation
Executive Committee CEO · CIO · CISO · Legal DORA · NIS 2 · Cloud Act
Pejman Gohari · CDO · Chief AI Officer · ORBii
25 years in the field · DataLab SG · Data Factory Bpifrance · BPCE SI · DUNOD Author · IESEG Professor
academy.orbii.tech
ORBii.Academy · D4 · Digital Sovereignty · Executive Leaders TrackConfidential · 202601
D4 · Sovereignty · 02
Section 1

The 4 dependency risks the Executive Committee must understand

Risk 1 · Jurisdictional
Cloud Act vs GDPR — an unresolved conflict

The US Cloud Act requires US providers (AWS, Azure, Google Cloud) to disclose data to American authorities upon judicial request — even when that data is hosted in Europe. This directly contradicts the GDPR. An executive who stores sensitive data with a US provider accepts this risk.

EXECUTIVE COMMITTEE DECISION

Which company data must never be accessible to a foreign jurisdiction? Define the list and migrate to sovereign hosting.

Risk 2 · ICT Concentration (DORA)
Over-reliance on a single critical vendor

DORA requires measuring and limiting ICT concentration risk. If a single vendor hosts 60%+ of your critical systems, an outage or commercial disruption paralyzes operations. The regulator can demand a remediation plan.

EXECUTIVE COMMITTEE DECISION

Set a maximum dependency threshold per critical ICT vendor and an 18-month diversification plan.

Risk 3 · Algorithmic
Your vendor's AI, not yours

When your credit scoring or risk management tool is a proprietary AI model from an external vendor, you control neither the training data, nor the logic, nor the evolution. A vendor update can alter your decisions without your knowledge.

EXECUTIVE COMMITTEE DECISION

For every critical AI: contractually require update traceability and the right to audit the model.

Risk 4 · Skills & Capabilities
When expertise leaves the organization

Massive outsourcing of data and AI depletes the organization of its critical skills. If your key data scientist leaves, if your provider is acquired, you lose the ability to regain control. Skills sovereignty is as strategic as data sovereignty.

EXECUTIVE COMMITTEE DECISION

Identify the 5 critical data/AI skills that are strategically dangerous to outsource entirely.

ORBii.Academy · D4 · Digital Sovereignty · Executive Leaders TrackConfidential · 202602
Protected Content

You have viewed the preview of this module (first 2 pages).
To access the full content, enter your access code or request access.

3 pages remaining Personal link · Valid 24h