Data storage graphic
– Getty Images

For the past 18 months, the idea of digital autonomy and control has been bandied about by vendors across the globe through the "s" word: sovereignty. Whether operational, infrastructure-focused, or data governance, the concept has snowballed from a legal concept about borders to a multilayered administrative must-have.

For anyone sick of this abstruse topic, however, we may only just be at the start of the sovereignty conversations, in the view of Beyond.pl CEO Wojciech Stramski.

“Changing your strategy, if you’re a big enterprise [or] financial institution, it doesn't happen overnight,” the data center leader explained to SDxCentral. “It's starting with the more mature entities that have the capacity, the resources to make that transition from an existing strategy, which wasn't so sovereign, to one which is much more sovereign, but it's trickling down to the entities below and it doesn't happen overnight.”

Wojciech Stramski
Beyond.pl CEO Wojciech Stramski

Stramski was speaking with this title at the recent Everpure vendor conference in London, where the flash-storage kings published stark survey results in which 90% of respondents said they recognize data sovereignty as a business concern, and yet 64% of those surveyed lack a formal strategy.

Stramski’s comments, while being those of an Everpure partner in part through its so-called AI factory deployment in Poland, come as Europe is arguably the continental king when it comes to waving the sovereignty banner. Stuck between a U.S. and a Chinese place, Europe’s aggressive data and privacy regulations – from the GDPR to the recently transposed Data Act – aim to balance big tech dominance with fostering its own infrastructure offerings.

The CEO’s firm was among the first of Europe’s sovereign AI factories, but relies on Nvidia hardware, with B2000 GPUs paired with Pure’s FlashBlade//S for fast file and object workloads. Beyond.pl uses other arrays beyond Everpure.

When asked about marrying a reliance on American hardware with services billed as being sovereign, Stramski outlined that there are different levels of what it means to be inherently sovereign and that said deployments stem from the reality that there is “no real alternative today.”

“What we serve out of the data center in Poland, for example, in the AI factory, all the data is processed locally, stored locally. The models are local, so there is no exchange of information,” the CEO explained. “Sovereignty is super important. I think it's driving the majority of decisions. If you're looking at enterprises in Europe, the sovereignty element is what's driving everything, and it's driving the EU agenda, country agenda, and also enterprise agenda.”

In a slight twist of irony, then, for all the chatter about sovereignty, Stramski revealed to SDxCentral that the majority of Beyond.pl customers were those inbounding to its site to deliver sovereign services for their European base.

“These customers are very diligent, I would say, because we're dealing with financial institutions and other entities that are very strict,” Stramski added.

Patrick Smith, Everpure’s EMEA CTO speaking at Accelerate London 2026
Everpure’s Patrick Smith speaking at Accelerate London 2026 – Ben Wodecki/SDxCentral

High stakes, higher risks?

Everpure’s analysis of IT leaders’ sovereign stances didn’t solely encompass European vendors. Some 2,100 responses were recorded from Australia, Japan, South Korea, Singapore, and India.

Among the findings was that key risk priorities around the concept of data sovereignty were misaligned. Almost half (47%) cited cybersecurity, while 26% cited service disruption from undefined “political uncertainties.”

The finding Everpure leaders said they found to be the most stark was that just 9% of surveyed IT leaders expressed concern over extraterritorial data access.

“We felt that this was a really low number,” Patrick Smith, Everpure’s EMEA CTO, said during a press briefing. “This, for us, smacks at the fact that they're dealing with what the regulator says you need to do rather than actually looking at your own organization, your own data, and the risk of that data falling into the wrong hands.”

Another surprisingly low stat was that 9% admitted to the concentration of large cloud environments as a risk, which is arguably one of the key catalysts that kicked off the whole sovereignty conversation.

“If you look beyond data sovereignty and you look at the whole operational risk question, we see an overlap between some of the sovereignty aspects and some of the operational resilience aspects that I think that calls out,” Smith added.

In a later fireside chat between Smith, Stramski, and Everpure’s Ashish Gupta, the Beyond.pl CEO said the 9% figures jumped out, but that in Europe and Poland “in general they would be much higher.”

“There were entities that were looking at sovereignty from a compliance perspective, complying [with] GDPR, but they weren't really looking beyond that,” Stramski said. “I think what's become very clear, especially in the hyperscaler ecosystem, is the risk and the worry about what happens if the administration in the U.S. decides to shut off the services to these specific entities [or] tap in and get access to the data of these enterprises … these are questions being asked, so from a sovereignty perspective, I would tend to argue that that 9% number is much much higher in in the majority of the European enterprise markets.”

Sovereignty as an idea in the sense of enterprise data protection and governance is a business concern, but perhaps the most interesting finding from Everpure’s survey was that 88% of respondents were concerned that a related mishap could jeopardize the jobs of senior leaders.

In Smith’s view, surveyed leaders’ concern that their own positions could be at risk shows there’s an “understanding in terms of the criticality of data sovereignty.”