Multi-Cloud Strategy for the Federal Administration: Architecture, Procurement and Compliance

AI In The Public Sector, Azure CAF & Cloud Migration, Sovereignty Series 22nd Aug 2026 Martin-Peter Lambert
Multi-Cloud Strategy for the Federal Administration: Architecture, Procurement and Compliance

Single cloud providers have their limits. A multi-cloud strategy overcomes them: Azure, Google Cloud, the Deutsche Verwaltungscloud and sovereign platforms complement each other, and the result is maximum flexibility with full compliance. This article builds on our Cloud Migration Roadmap for the Public Sector.

Multi-cloud architecture for the public sector: governance, connectivity, security and application layers

Multi-Cloud is the Future of Public Sector IT

The public sector benefits particularly: specialised workloads find their optimal platform, and digital sovereignty is maintained by placing each workload where its protection needs are met — not where the first contract happened to be signed.

What Multi-Cloud Really Means

Multi-cloud is more than just using two providers. It is a strategy, an architecture, and an operating model. The Cloud Adoption Framework for Azure provides the methodology; a GCP Landing Zone provides the structure; a sovereign landing zone covers the workloads that must stay under EU control.

Each workload is analysed. Where does it run best? Azure? GCP? A sovereign cloud in Germany? The answer is often: it depends — on data classification, required services, cost and exit strategy.

The Building Blocks of a Multi-Cloud Architecture

Governance Layer — Centralised control is essential. Azure and GCP landing zones follow common principles: uniform policies as code, consistent monitoring, and end-to-end security.

Connectivity LayerAzure ExpressRoute connects data centres; Google Cloud Interconnect complements it. Hybrid scenarios become possible and datacenter migration proceeds without interruption — see Multi-Cloud Connectivity.

Security LayerBSI C5 applies across the board. One BSI-compliant cloud security concept covers all platforms; IT-Grundschutz in the cloud and ISO 27001 remain the standard.

Application Layer — This is where multi-cloud shows its strength. Kubernetes runs on AKS, GKE and sovereign platforms alike. Containers are portable. Vendor lock-in is avoided.

Quick Checklist: Multi-Cloud Readiness

AreaCheckpointStatus
GovernanceCentral Policy Engine Defined
NetworkConnectivity Concept Created
SecurityBSI C5 Mapping for All Clouds
IdentityCentralised IAM Planned
CostsFinOps Process Established
OperationsMulti-Cloud Monitoring Active
ExitPortability and exit plan tested per workload

To-Do List for Multi-Cloud Success

  1. Immediately: Conduct a cloud strategy workshop.
  2. Week 1: Start workload classification.
  3. Week 2: Create a compliance matrix.
  4. Month 1: Build landing zones in parallel.
  5. Month 2: Migrate pilot workloads.
  6. Month 3: Establish governance processes.

Structuring Tenders and Procurement Correctly

A cloud migration tender requires expertise. The procurement of cloud service providers follows public procurement law (VgV, EVB-IT); a cloud framework agreement accelerates procurement. Consulting should begin before the tender so that requirements — C5 Type 2 attestation, DVC conformity, EU operator control, exit clauses — are written into the specification and offers become comparable.

Migration costs vary widely. A fixed-price migration creates certainty, provided the assessment phase has produced a reliable inventory.

Compliance as an Enabler

Being BSI C5 compliant is not an obstacle; it is a mark of quality. KRITIS cloud security becomes the standard and NIS2 integrates European requirements. A Data Protection Impact Assessment for the cloud is mandatory — it protects citizens and the authority alike.

The Insight42 Approach

We understand multi-cloud, public authorities and procurement. From strategy to operations we deliver landing zones, migration and managed services across Azure, GCP and sovereign platforms from a single source.

Start now. See Souveräne Cloud Beratung (German) or contact us.

Multi-Cloud Connectivity: Combining Azure ExpressRoute and Google Cloud Interconnect

AI In The Public Sector, Azure CAF & Cloud Migration 22nd Aug 2026 Martin-Peter Lambert
Multi-Cloud Connectivity: Combining Azure ExpressRoute and Google Cloud Interconnect

Multi-cloud is a reality for the German public sector: Azure and Google Cloud are used in parallel. But how do you connect both securely — without routing sensitive data over the public internet? This article extends our guide to Azure ExpressRoute for public authorities to the multi-cloud case.

Multi-Cloud Needs Multi-Connectivity

The answer is dedicated lines to both clouds: Azure ExpressRoute for Microsoft and Google Cloud Interconnect for GCP. Both operate on similar principles and offer enterprise-grade security.

Understanding Google Cloud Interconnect

Cloud Interconnect is Google’s equivalent of ExpressRoute. Dedicated Interconnect provides physical connections, while Partner Interconnect uses carrier infrastructure.

Interconnect is crucial for a GCP migration: large data volumes must be transferred, and GKE workloads benefit from low latency.

A hub and spoke network topology for multi-cloud connectivity

The Architecture for Multi-Cloud

Central Network Hub — A hub connects everything: on-premises, Azure, and GCP. Routing is centrally controlled, and security is uniformly enforced.

ExpressRoute to the Azure Hub — Private Peering connects to Azure VNets. A hub-and-spoke topology distributes traffic. The Azure Landing Zone is the destination.

Interconnect to the GCP Hub — Use either Dedicated or Partner Interconnect. A Shared VPC receives the traffic. The GCP Landing Zone takes over.

Inter-Cloud Connection — Azure and GCP can also be connected directly through partner solutions or the central hub.

Quick Checklist: Multi-Cloud Connectivity

CloudConnection TypeBandwidthRedundancy
AzureExpressRouteAs neededDual Circuit
GCPDedicated InterconnectAs neededDual Attachment
Inter-CloudPartner/HubAs neededActive-Active

To-Do List for a Multi-Cloud Network

  • Week 1: Conduct a traffic analysis.
  • Week 2: Create a connectivity design.
  • Week 3: Prepare the carrier tender.
  • Month 1: Order ExpressRoute.
  • Month 2: Order Interconnect.
  • Month 3: Optimise routing.
  • Month 4: Establish monitoring.

VPN as a Backup and Entry Point

Not every authority needs dedicated lines immediately. VPN is a valid entry point. A Site-to-Site VPN connects securely at a lower cost. Azure VPN Gateway and Cloud VPN from GCP both support IPsec and offer high availability; they are often sufficient for smaller workloads.

The transition to ExpressRoute or Interconnect can happen later when bandwidth or latency become critical — a decision we typically make in the cloud migration assessment.

Connectivity Compliance

Being BSI C5 compliant also means secure connections. The BSI-compliant cloud security concept must address connectivity. Encryption is mandatory, even on dedicated lines.

A Data Protection Impact Assessment for the cloud considers data flows. Where does data flow? Via which paths? These questions must be answered.

Optimising Costs

Multi-cloud connectivity is not cheap, but it is necessary. FinOps approaches help with optimisation: traffic routing is analysed, egress costs are allocated, and a fixed-price migration offer should include connectivity transparently.

Insight42 Multi-Cloud Network Services

We design multi-cloud networks, providing ExpressRoute and Interconnect from a single source for secure, performant, and cost-effective solutions — with managed services that monitor the connections proactively under SLA.

Connect your clouds. See Cloud Migration Beratung (German) or contact us.

Conditional Access and MFA: Intelligent Access Control for the Public Sector

AI In The Public Sector, Security 22nd Aug 2026 Martin-Peter Lambert
Conditional Access and MFA: Intelligent Access Control for the Public Sector

Old access models are obsolete. Once authenticated, always trusted? Dangerous. Conditional Access changes the game: every access is evaluated, context is key. This article follows on from our guide to Entra ID migration for public authorities and shows how to design the policies that make Zero Trust real.

Rethinking Access Control

For the public sector this is a step change. Security becomes dynamic, user-friendliness is maintained, and a cloud-first administration becomes defensible in front of auditors.

What Conditional Access Does

Conditional Access is a policy framework that evaluates access in real time. Who? From where? With what device? To what? These questions are answered on every sign-in.

Based on the answers, decisions are made: allow access, block access, require MFA, or restrict the session.

Understanding the Signals

User and Group — Who is accessing? Administrators have different rules than standard users. Externals different from internals.

Location — Where is the access coming from? Known networks are more trustworthy. Unknown countries are blocked.

Device — Is the device managed? Is it compliant? Unknown devices require additional verification.

Application — Which app is being accessed? Sensitive applications need stronger protection.

Risk — Entra ID automatically assesses sign-in and user risk. Unusual behaviour is detected. Compromised accounts are locked.

Quick Checklist: Conditional Access Policies

PolicyGoalAction
MFA for AdminsProtect privileged accountsEnforce MFA
Blocked CountriesStop attacks from high-risk regionsBlock access
Compliant DevicesAllow only secure devicesRequire compliance
Block Legacy AuthPrevent insecure protocolsBlock
Session TimeoutReduce risk during inactivityLimit session
App ProtectionProtect sensitive appsRequire MFA + Compliance

To-Do List for Conditional Access

  • Day 1: Activate report-only mode.
  • Week 1: Define baseline policies.
  • Week 2: Enforce MFA for all admins.
  • Week 3: Block legacy authentication.
  • Month 1: Introduce device compliance.
  • Month 2: Implement location-based policies.
  • Month 3: Implement risk-based policies.

Comparing MFA Methods

Not all MFA methods are equal. Some are more secure, others more user-friendly. The right choice depends on the context.

Microsoft Authenticator — Push notifications are simple. Number matching increases security. Passwordless login is possible.

FIDO2 Security Keys / Passkeys — Hardware-based and phishing-resistant. Ideal for high-security environments and administrators. Slightly higher cost.

SMS and Phone — Easy to implement, but less secure. Recommended only as a fallback.

Windows Hello for Business — On-device biometrics. Very user-friendly. Requires compatible hardware.

Meeting Compliance Requirements

BSI C5 demands strong authentication; Conditional Access delivers it. ISO 27001 based on IT-Grundschutz requires documented access control; Conditional Access logs every decision. NIS2 recommends Zero Trust; Conditional Access is a core component and supports the Data Protection Impact Assessment for cloud services.

Integration with Other Services

Conditional Access does not stand alone. It integrates with Microsoft Defender, uses Intune for device compliance, and connects to a SIEM (e.g., Microsoft Sentinel) for monitoring. A well-designed Azure Landing Zone includes the Conditional Access baseline from day one, and managed services keep the policies monitored.

Insight42 Conditional Access Services

We design Conditional Access strategies tailored for public authorities — compliant with BSI C5 and IT-Grundschutz, and user-friendly. From analysis to implementation and managed operations.

Control access intelligently. See NIS2 & Cloud Security Beratung (German) or contact us.

KI im Unternehmen: Warum die meisten Projekte scheitern — und wie Sie KI liefern, die Ihre Compliance-Abteilung freigibt

AI In The Public Sector 22nd Aug 2026 Martin-Peter Lambert
KI im Unternehmen: Warum die meisten Projekte scheitern — und wie Sie KI liefern, die Ihre Compliance-Abteilung freigibt

Jeder Vorstand will KI auf der Roadmap. Die meisten Unternehmen bekommen eine Chatbot-Demo, Compliance-Kopfschmerzen und einen gestoppten Pilot. Hier ist, was in europäischen KI-Projekten wirklich schiefläuft — und die Architektur, mit der Sie vom Proof-of-Concept zur Produktion kommen, ohne Ihre Daten, Ihr Budget oder Ihre DSGVO-Position aufs Spiel zu setzen.

Die unbequeme Wahrheit über Unternehmens-KI 2026

Der Druck ist real: Wettbewerber kündigen Copiloten an, der EU AI Act ist in Kraft, und „Wie sieht unsere KI-Strategie aus?“ ist zur Vorstandsfrage geworden. Doch die meisten KI-Initiativen in Unternehmen kommen nie über die Pilotphase hinaus. Nicht weil die Modelle schwach wären — heutige Modelle sind erstaunlich — sondern weil die Projekte drumherum die vier Zwänge ignorieren, die die europäische Realität prägen: Datenschutz, Datenreife, Souveränität und Rechenschaftspflicht.

Bei Insight42 bauen wir KI-Systeme für Organisationen, bei denen „move fast and break things“ keine Option ist — regulierte Branchen, der öffentliche Sektor und Unternehmen, die schlicht nicht bereit sind, Kundendaten in eine Blackbox im Ausland zu schicken. Dieser Artikel destilliert, was wir im Feld sehen: die Herausforderungen, die KI-Projekte töten, den Ansatz, der funktioniert, und die Vorteile, die Sie tatsächlich messen können.

Fünf Herausforderungen, die europäische KI-Projekte töten

1. Die Compliance-Mauer

DSGVO, der EU AI Act, Branchenregeln wie BSI C5 — bis die Rechtsabteilung ein US-gehostetes KI-Tool geprüft hat, ist die Dynamik des Piloten tot. Der Versand personenbezogener Daten an Drittland-APIs wirft Schrems-II-Fragen auf, die kaum ein Anbieter beantworten kann, und „der Anbieter sagt, das sei in Ordnung“ ist in einem Audit keine verteidigbare Position.

2. Daten, die nicht bereit sind

Modelle sind nur so gut wie die Daten, die sie erreichen. In den meisten Organisationen liegen diese Daten in Silos, ohne Governance, und enthalten personenbezogene Informationen, die niemand klassifiziert hat. Ein Sprachmodell auf diese Landschaft anzusetzen schafft keine Intelligenz — es schafft selbstbewussten Unsinn mit einem Datenschutzproblem.

3. Vendor-Lock-in als Bequemlichkeit getarnt

Der einfachste Weg — die gebündelte KI-Suite eines Hyperscalers — wird still und leise zum teuersten. Preise ändern sich, Modelle werden abgekündigt, und die Wechselkosten wachsen mit jedem verdrahteten Workflow. Souveränität ist keine Ideologie; sie ist Verhandlungsmacht.

4. Halluzination ohne Rechenschaftspflicht

Ein Modell, das in einem Consumer-Chat eine Antwort erfindet, ist amüsant. Dasselbe Verhalten in einer Beschaffungsentscheidung, einem Bürgerservice oder einem medizinischen Kontext ist eine Haftungsfrage. Ohne Grounding, Evaluation und menschliche Aufsicht ist generative KI eine Risikomaschine — und der EU AI Act verlangt jetzt den Nachweis des Gegenteils.

5. Piloten ohne Weg zur Produktion

Die Demo beeindruckt; dann kommt die Realität: Identität und Zugriff, Logging, Kostenkontrolle, Monitoring, Updates. Die meisten Piloten waren nie darauf ausgelegt, den Kontakt mit dem IT-Betrieb zu überleben — also überleben sie ihn nicht.

Der Insight42-Ansatz: Souveräne KI, technisch sauber umgesetzt

  • Souveräne Architektur als Standard. EU-Region oder On-Premises-Bereitstellung, Ihre Schlüssel (BYOK/HYOK), Ihre Datenresidenz. Das Modell kommt zu Ihren Daten — Ihre Daten werden nie zu den Trainingsdaten von irgendjemand anderem.
  • Grounded Generation (RAG) auf governten Daten. Wir verbinden Modelle über Retrieval mit Ihren Dokumenten und Systemen — mit Quellenangaben — damit Antworten auf Ihr eigenes Wissen zurückführbar sind, nicht auf die Fantasie des Internets.
  • Agentische Automatisierung mit Mensch in der Schleife. KI-Agenten, die mehrstufige Workflows ausführen — Triage, Entwürfe, Abgleich — innerhalb von Leitplanken, mit Freigabe-Gates dort, wo der Einsatz es verlangt. Mehr dazu in unserer Agentic AI Beratung.
  • EU-AI-Act-Konformität by Design. Risikoklassifizierung, Dokumentation, Logging und Evaluation sind Teil der Lieferung — nicht vor dem Audit angeklebt.
  • Eine Use-Case-Pipeline statt eines Mondschusses. Wir beginnen dort, wo ROI in Wochen nachweisbar ist — dann skalieren wir, was funktioniert. Jeder Use Case bekommt eine Kennzahl, bevor er ein Modell bekommt.
  • End-to-End-Lieferung. Strategie, Datenplattform, Implementierung und Betrieb aus einem Team — keine Übergabeverluste zwischen Folie und Deployment.

Die Vorteile — in Zahlen, die Ihr CFO versteht

  • Durchlaufzeiten sinken: Dokumentlastige Prozesse (Support, Beschaffung, Reporting) beschleunigen sich spürbar, sobald grounded KI den ersten Entwurf übernimmt — die konkrete Kennzahl definieren wir pro Use Case vor dem Start.
  • Compliance wird zum Aktivposten: Auditierbare KI — mit Datenresidenz, Logging und dokumentierten Risikoklassen — macht aus „Dürfen wir KI einsetzen?“ eine Checkliste statt eines Blockers.
  • Keine Lock-in-Prämie: Modellagnostische Architektur bedeutet, Sie tauschen Modelle, wenn sich der Markt bewegt — und verhandeln aus einer Position der Stärke.
  • Wissen verlässt nicht mehr die Tür: RAG über Ihre eigene Dokumentation macht institutionelles Wissen durchsuchbar, zitierbar und ab Tag eins nutzbar.
  • Teams, die annehmen statt abzulehnen: Gemeinsam entwickelte Workflows und Schulungen machen aus KI ein Alltagswerkzeug statt einer Bedrohungserzählung.

Wo Sie anfangen

Wenn Sie eines aus diesem Artikel mitnehmen: Beginnen Sie nicht mit einem Modell — beginnen Sie mit einem Use Case, einer Kennzahl und Ihrer Datenrealität. Unsere Teams für Generative KI und Agentische KI führen genau diese Übung mit Kunden durch: ein fokussiertes Assessment, das in einer priorisierten, compliance-geprüften KI-Roadmap endet, die Sie noch in diesem Quartal umsetzen können. Wenn Ihre Daten eine EU-kontrollierte Infrastruktur verlangen, ist unsere Souveräne Cloud Beratung der passende Startpunkt.

Bereit, von KI-Folien zu ausgeliefertem Code zu wechseln? Agentic AI Readiness-Workshop buchen oder direkt mit unseren Ingenieuren sprechen.

Entra ID Migration for Public Authorities: The Path to Zero Trust

AI In The Public Sector, Azure CAF & Cloud Migration, Growth, Resilience, Sovereignty Series 18th Feb 2026 Martin-Peter Lambert
Entra ID Migration for Public Authorities: The Path to Zero Trust

Identity is the New Perimeter

Firewalls alone are no longer enough. Employees work from anywhere. Cloud services are distributed. Identity has become the central security anchor. Zero Trust is the answer.

This is particularly relevant for the public sector, where sensitive citizen data must be protected. A migration to Microsoft Entra ID creates the foundation for SSO, MFA and Conditional Access — and covers a substantial part of the identity and access management criteria in BSI C5, IT-Grundschutz and NIS2.

What Zero Trust Means

Zero Trust is a security model: never trust, always verify. Every access attempt is checked. Every identity is validated.

It sounds strict, and it is. But it works. Attacks are made more difficult. Lateral movement is prevented. A BSI-compliant cloud security concept recommends this approach.

The Pillars of Zero Trust

Verify Identity

Who is accessing the resource? Is the person who they claim to be? Multi-Factor Authentication is mandatory. Passwords alone are not enough.

Validate Device

From which device is the access coming? Is it managed? Is it compliant? Conditional Access checks these factors.

Minimise Access

The principle of least privilege applies. Only necessary rights, only for the necessary time. Just-in-Time access becomes the standard.

Monitor Activities

Every access is logged. Anomalies are detected. Automated responses are triggered.

Quick Checklist: Zero Trust Implementation

ComponentActionPriority
MFAEnable for all usersCritical
SSOSet up Single Sign-OnHigh
Conditional AccessCreate baseline policiesHigh
PIMImplement Privileged Identity ManagementHigh
Device ComplianceDefine device policiesMedium
App ProtectionConfigure application protectionMedium
MonitoringMonitor sign-in logsMedium

To-Do List for Entra ID Migration

  1. Immediately: Enable MFA for administrators.
  2. Week 1: Take inventory of identities.
  3. Week 2: Define the SSO strategy.
  4. Week 3: Plan Conditional Access policies.
  5. Month 1: Migrate a pilot group.
  6. Month 2: Roll out to all users.
  7. Month 3: Implement PIM.

SSO Simplifies and Secures

Single Sign-On is not a luxury; it is a security feature. Fewer passwords mean less risk. Users use strong passwords because they only need one.

Entra ID enables SSO for thousands of applications, both in the cloud and on-premises. SAML, OAuth, and OpenID Connect are all supported — which is why identity is usually the first workload in a public-sector cloud migration.

Implementing MFA Correctly

Multi-Factor Authentication is mandatory. BSI C5 compliance without MFA? Impossible. IT-Grundschutz and NIS2 require it as well.

But MFA must be user-friendly. Authenticator apps are standard. Biometrics where possible. Hardware tokens (FIDO2) for high security and phishing resistance.

Conditional Access makes MFA intelligent. Not for every login, only when there is a risk. Unknown device? MFA. Unusual location? MFA. We cover the policy design in detail in Conditional Access and MFA: Intelligent Access Control for the Public Sector.

Protecting Privileged Identities

Administrators are prime targets. Their accounts have extensive rights. Privileged Identity Management (PIM) protects them.

The principle is Just-in-Time access. Rights are activated only when needed, for a limited time, and with approval. A BSI-compliant cloud security concept and KRITIS cloud security both demand these controls.

Insight42 Identity Services

We plan and implement Entra ID migrations with Zero Trust as the default: SSO strategy, MFA rollout, Conditional Access baselines, PIM and monitoring — from strategy to operation, including managed identity services for public authorities.

Secure your identities. See NIS2 & Cloud Security Beratung (German) or contact us.

Azure ExpressRoute for Public Authorities: A Secure Connection to the Cloud

AI In The Public Sector, Resilience, Sovereignty Series 16th Feb 2026 Martin-Peter Lambert
Azure ExpressRoute for Public Authorities: A Secure Connection to the Cloud

Why ExpressRoute is Essential for Public Authorities

The public internet is not an option. Sensitive government data requires dedicated connections. An Azure ExpressRoute setup provides this security through private lines, guaranteed bandwidth, and low latency.

Cloud migration for the public sector demands reliable connectivity. A datacenter migration to Azure only works with a stable connection. ExpressRoute delivers both: security and performance.

Azure ExpressRoute architecture for public authorities: on-premises datacenter, carrier, private peering, Azure landing zone
Azure ExpressRoute architecture

What Azure ExpressRoute Offers

ExpressRoute is a private connection that completely bypasses the internet. Data flows over dedicated lines, with carrier partners providing the infrastructure.

For the public sector, this means the communication-security criteria of BSI C5 are easier to meet. The BSI-compliant cloud security concept can point to secure connectivity, strengthening KRITIS cloud security.

Understanding the Architecture

ExpressRoute Circuit — The circuit is the physical connection linking your data center to Microsoft. Various bandwidths are available, from 50 Mbps to 100 Gbps.

Peering Types — Private Peering connects to Azure VNets, while Microsoft Peering reaches Microsoft 365. Both can be used in parallel.

Redundancy — High availability requires redundancy. Two circuits at different locations ensure automatic failover in case of an outage, meeting government SLAs.

Quick Checklist: ExpressRoute Setup

StepTaskResponsible
1Determine Bandwidth NeedsIT Department
2Select Carrier PartnerProcurement
3Order CircuitCarrier
4Configure AzureCloud Team
5Set Up RoutingNetwork Team
6Implement RedundancyCloud Team
7Activate MonitoringOperations

To-Do List for Secure Connectivity

  1. Today: Analyse current bandwidth usage.
  2. This Week: Research carrier options.
  3. This Month: Create the ExpressRoute design.
  4. Quarter 1: Commission the circuit.
  5. Quarter 2: Start migration over ExpressRoute.

Mastering Hybrid Scenarios

Not everything moves to the cloud at once. Hybrid architectures are a reality. ExpressRoute connects both worlds, allowing on-premises and Azure to work together.

A VMware to Azure migration particularly benefits, as large data volumes are transferred quickly. Replication runs in the background, and the cutover occurs without significant downtime.

Security at All Levels

ExpressRoute is private by design, but it is not encrypted by default. Additional measures — MACsec on the circuit, IPsec tunnels over ExpressRoute, or application-level TLS — provide the encryption that BSI C5 and IT-Grundschutz expect even on dedicated lines.

IT-Grundschutz recommends defence in depth: ExpressRoute is one layer, complemented by firewalls, segmentation and identity-based access control.

Costs and Procurement

Azure ExpressRoute has two cost components: Microsoft charges for the circuit, and the carrier charges for the line. Both must be budgeted.

A cloud framework agreement can simplify procurement, and a cloud migration tender should include connectivity from the start so that total migration costs stay transparent.

Insight42 Connectivity Services

We plan and implement ExpressRoute, from needs analysis to operation, as part of our Azure migration consulting — and our managed services monitor the connection proactively for SLA-compliant operation. For multi-cloud environments see Multi-Cloud Connectivity: Combining ExpressRoute and Google Cloud Interconnect.

Connect securely. See Cloud Migration Beratung (German) or contact us.

AI Won’t Replace People. Bad Incentives Will.

AI In The Public Sector, Azure CAF & Cloud Migration, Sovereignty Series 13th Feb 2026 Martin-Peter Lambert
AI Won’t Replace People. Bad Incentives Will.

The real danger isn’t intelligent machines—it’s incompetent governance. Systemic incentives have a far greater impact than technology alone. True ROI comes from building AI and automation that augments your team, on a cloud foundation you actually control. This article argues why “AI won’t replace people, bad incentives will” should be the real focus of the debate.

AI is Capital: Treat It Like Capital

The discourse surrounding Artificial Intelligence is dominated by futuristic fantasies, obscuring a critical reality: AI is a form of capital — part of the new cloud capital, but more potent. Its value is realised not in the lab but in its effective deployment. The true measure of AI is its impact on the customer and the bottom line. As a professional services company, Insight42 focuses on building AI and automation solutions that deliver tangible business results.

AI as capital: value is realised in deployment, not in the lab

23. AI is not magic; it’s applied statistics plus compute plus workflow integration.

The mystique surrounding AI is a marketing gimmick. The value is unlocked by its application to solve a real-world problem. Demos are easy; deployment is hard. Our expertise in building BI, data warehouses, automation, data analytics and AI focuses on the practical, operational challenges of making AI work in your specific business context.

24. ROI lives in process redesign, not model accuracy.

A highly accurate AI model that isn’t integrated into a redesigned business process is a worthless curiosity. The real return on investment comes from rethinking how work gets done. This is a management challenge. As your partner, we help you with the process redesign necessary to realise the full potential of your investment in AI and automation.

25. The bottleneck is humans-in-the-loop design.

The most effective AI systems augment humans, not replace them. The bottleneck in AI adoption is the design of the human-computer interface. When we build internal tools or AI agents, our focus is on creating a seamless user experience that empowers your team to make better decisions, faster.

26. The first AI win is usually “time back,” not headcount down.

The initial impact of AI is the automation of tedious tasks, freeing up human workers for higher-value activities. This increases productivity and employee satisfaction. Our professional services for building AI and automation aim to empower your workforce, not replace it.

The Model Economy: Costs, Risks, and Rents

The rise of AI has created a new economic landscape. Navigating this requires a partner who understands not just the technology, but also the underlying economics, from the cost of your cloud migration to the long-term resilience of your models.

The model economy: inference cost, data gravity and open models

27. Inference cost is the new unit economics.

The cost of running an AI model in production can quickly spiral out of control. When building your cloud for AI, we design cost-aware architectures that minimise inference costs without sacrificing performance, ensuring your AI initiatives are profitable.

28. Data gravity will decide winners.

Data has mass. The winners in the AI economy will be those who can place their computing resources close to their data. Our cloud migration services are designed with data gravity in mind, helping you choose the right architecture to minimise latency and egress costs.

29. Open models reduce monopoly pricing pressure.

Open-weight models are a powerful force for competition. As part of our services for building AI, we leverage open-source technologies where appropriate to reduce costs and prevent vendor lock-in, giving you more control over your technology stack.

30. AI safety is governance of incentives, not just policies.

A safe AI is one governed by incentives aligned with human values. This requires a focus on truthfulness and auditability — logged decisions, traceable sources and clear approval points, the same principles we build into every production agent.

Human Rights and High Performance Can Be Allies

A commitment to human rights can be a source of competitive advantage, building the trust essential for the widespread adoption of AI. This requires a focus on security and transparency.

Governing AI incentives: due process and operational transparency

31. Due process for automated decisions isn’t “red tape”—it’s legitimacy.

As AI makes increasingly important decisions, the need for due process is paramount. The ability to challenge an automated decision is a fundamental requirement — and under the EU AI Act a legal one for high-risk systems. Our approach to building AI includes creating systems with clear audit trails and human oversight.

32. Transparency must be operational, not philosophical.

True transparency is about understanding the inputs, outputs, and consequences. It’s about creating clear escalation paths. When building BI, data warehouse or AI systems, we prioritise operational transparency to ensure your systems are trusted and adopted.

Build an AI-Powered Future That Works for Your Business

Is your AI strategy built for the future? At Insight42, we design and implement AI strategies that are powerful, profitable, and responsible:

Contact us for a consultation and let Insight42 help you build an AI-powered future that drives real business value.

Europe, Stop Renting Your Future: The Cloud Dependency Trap Nobody Wants to Price In

AI In The Public Sector, Azure CAF & Cloud Migration, Sovereignty Series 10th Feb 2026 Martin-Peter Lambert
Europe, Stop Renting Your Future: The Cloud Dependency Trap Nobody Wants to Price In

If your compute, storage, and identity rails are leased, your “sovereignty strategy” is just a press release. True independence requires a cloud strategy with a priced-in exit — and a clear path to digital freedom.

The Bill You Don’t See (Until It’s Due)

For too long, European enterprises have approached cloud adoption as a purely technical decision. This is a profound and costly mistake. The reality is that the cloud is a balance-sheet decision, with hidden liabilities that can cripple an organisation’s financial health and strategic independence. As Milton Friedman taught, incentives are everything. When your provider’s incentives aren’t aligned with yours, you need a partner on your side of the table.

The hidden bill of cloud dependency

1. Cloud is a balance-sheet decision, not a tech preference.

The allure of the cloud is its apparent simplicity. However, this masks liabilities like vendor lock-in and punitive egress fees. These are financial risks. A true accounting of cloud costs must include the cost of data extraction and the risk of service disruption. Our cloud migration assessments include a comprehensive financial analysis so that your move to the cloud is not only technically sound but also financially prudent, with a clear view of the total cost of ownership.

2. The cheapest cloud is often the most expensive option.

The siren song of low unit costs has lured many enterprises onto the rocks of cloud dependency. The initial savings are often eroded by escalating fees and the difficulty of migrating. The “cheap” cloud becomes an expensive landlord. A wise IT leader looks beyond the initial price to long-term resilience and cost control.

3. If you can’t leave in 90 days, you don’t have a supplier—you have a landlord.

A true supplier relationship is one of voluntary exchange. If you are unable to switch providers, you are a tenant. The ability to exit is the ultimate guarantee of fair pricing. We design exit strategies from day one — and test them — so that you maintain control and flexibility.

4. Resilience beats optimisation when geopolitics enters the room.

The pursuit of efficiency at all costs is dangerous. A resilient cloud strategy prioritises redundancy and diversification, ensuring business continuity no matter the external conditions.

Hardware is Strategy (Whether You Admit It or Not)

Europe’s digital ambitions are built on a foundation of sand. A true digital sovereignty strategy must begin with a clear-eyed assessment of the hardware reality.

Hardware as strategy: chips, energy and firmware

5. No chips, no sovereignty.

Without a robust domestic semiconductor industry, Europe will remain a digital vassal. This is a matter of national security — and, at enterprise level, a reason to reduce dependency on single-source suppliers wherever the architecture allows it.

6. Energy is the new compute moat.

A stable and affordable supply of energy is the new moat that will protect a nation’s digital infrastructure. Data-centre energy efficiency and stability belong in every long-term cloud cost model.

7. Security starts below the OS.

Firmware, the supply chain, and trusted execution environments are the new front lines of cybersecurity. A secure cloud is secure from the silicon up — see Building on Bedrock, Not Sand.

A European Cloud That Isn’t a Bureaucratic Cosplay

The dream of a sovereign European cloud is noble, but it is in danger of becoming a bureaucratic nightmare. A true sovereign cloud is about control, interoperability, and the right to exit.

A shield protecting a network of servers: sovereign cloud as control of keys and identity

8. Sovereign cloud isn’t “local hosting.” It’s control of keys, identity, and enforcement boundaries.

True sovereignty lies in the control of encryption keys and user identities. Robust identity and access management and customer-controlled key management give you that control — whichever provider hosts the hardware.

9. Interoperability is the antidote to monopoly rent.

Open standards and portable applications are the keys to a competitive cloud market. Our migration strategies prioritise interoperable technologies, including containerisation and open-source solutions, to prevent vendor lock-in.

10. Procurement can create a market—or kill one.

By prioritising outcomes like portability and auditability, governments can create a more competitive cloud market. We help clients define procurement requirements that foster innovation and give them the flexibility to choose best-of-breed solutions.

11. Build a “right to exit” into every public IT programme.

The most pro-competition policy is a universal “right to exit.” Every IT contract should include a clear exit provision. We help you negotiate these terms to ensure your long-term freedom and control.

Take Control of Your Digital Future with Insight42

Is your organisation trapped in the cloud dependency cycle? Don’t just move to the cloud—migrate with a strategy:

Contact us for a consultation and let Insight42 help you take the first step towards true digital independence.

Cloud Migration Roadmap for the Public Sector: The Path to Digital Sovereignty

AI In The Public Sector, Resilience, Sovereignty Series 9th Feb 2026 Martin-Peter Lambert
Cloud Migration Roadmap for the Public Sector: The Path to Digital Sovereignty

Why Public Authorities Need a Cloud Strategy Now

The digital transformation of public administration is at a turning point. A cloud-first approach is no longer an option; it is a necessity. German authorities must act, and time is of the essence — the Deutsche Verwaltungscloud has become a product, sovereign offerings from AWS, Delos, STACKIT and IONOS are live, and BSI C5:2026 sets the new bar.

A well-designed Cloud Migration Roadmap provides the foundation. It connects technical requirements with regulatory mandates, placing BSI C5 compliance at the core. The ultimate goal is to achieve digital sovereignty in the cloud.

Cloud migration roadmap for the public sector: five phases from assessment to operations

Understanding the Challenge

Public institutions face unique hurdles. A Data Protection Impact Assessment (DPIA) for the cloud is mandatory. IT-Grundschutz must be involved from the start. The procurement of cloud service providers follows strict regulations.

A multi-cloud strategy offers flexibility: Azure and GCP migrations can proceed in parallel, the Cloud Adoption Framework for Azure provides proven methodology, and sovereign platforms complete the ecosystem for workloads with the highest protection needs.

The 5-Phase Approach to Cloud Migration

Phase 1: Assessment and Analysis — Every successful migration begins with an inventory. What workloads exist? What are the dependencies? What protection needs does each carry?

Phase 2: Strategy and Architecture — This is where the actual roadmap is developed. Azure Landing Zone or GCP Landing Zone? Often, the answer is both. Multi-cloud enables freedom of choice.

Phase 3: Compliance and Security — BSI C5 requirements are defined. A BSI-compliant cloud security concept is created. ISO 27001 based on IT-Grundschutz forms the basis.

Phase 4: Migration and Implementation — The datacenter migration is performed step-by-step in waves. VMware-to-Azure migrations use proven tooling. A fixed-price migration offer provides planning security.

Phase 5: Operations and Optimisation — Managed services take over routine operations and ensure availability. Continuous improvement becomes the standard.

Quick Checklist: Cloud Migration Roadmap

StepActionTimeline
1Create Workload InventoryWeek 1-2
2Document Compliance RequirementsWeek 2-3
3Evaluate Cloud ProvidersWeek 3-4
4Plan Landing ZoneWeek 4-6
5Launch Pilot ProjectWeek 6-8
6Finalise Rollout PlanWeek 8-10

To-Do List for Decision-Makers

  1. Today: Appoint an internal cloud champion.
  2. This Week: Initiate an IT landscape assessment.
  3. This Month: Commission an independent cloud readiness assessment.
  4. Quarter 1: Conduct a BSI C5 gap analysis.
  5. Quarter 2: Prepare the cloud migration tender.

Why Multi-Cloud Makes Sense for Public Authorities

A single sovereign cloud alone is often not enough. Specialised services require flexibility. The Deutsche Verwaltungscloud can be combined with Azure, GCP, the AWS European Sovereign Cloud or STACKIT — per workload, by protection need.

The advantages are clear: no vendor lock-in and the best solution for every use case. A cloud framework agreement enables rapid procurement, and comparable offers keep migration costs predictable. We go deeper in Multi-Cloud Strategy for the Federal Administration.

The Next Step

A professional Cloud Migration Roadmap is complex. It requires expertise in technology, compliance and procurement law. Insight42 supports public authorities on this journey, from the initial analysis to ongoing operations — with BSI C5, IT-Grundschutz and NIS2 built into the architecture.

Ready for the first step? See Cloud Migration Beratung (German) or contact us for a non-binding initial consultation.

Beyond the Wall: Mastering the Digital Sovereignty Trilemma in a Fragmented World

AI In The Public Sector, Resilience, Sovereignty Series 27th Jan 2026 Martin-Peter Lambert
Beyond the Wall: Mastering the Digital Sovereignty Trilemma in a Fragmented World

January 27, 2026 – The digital landscape is shifting beneath our feet. While today’s headlines focus on localized outages and the fragility of global AI dependencies, a deeper, more structural challenge is emerging for European leaders. It is the Digital Sovereignty Trilemma: the “Impossible Trinity” of Sovereignty, Resilience, and Safety. In fact, this issue is central to the ongoing debate on European Safety, Sovereignty and Resilience.

For years, we’ve been told we can have it all. But as the EU pushes for strategic autonomy while its businesses crave the raw power of Silicon Valley’s innovation, the cracks are showing. This isn’t just a regulatory hurdle; it’s a management masterclass in trade-offs where European Safety, Sovereignty and Resilience are at stake.

The Anatomy of the Conundrum

To understand how to win, we must first understand why we often lose. The trilemma forces us to choose between three essential but competing pillars:

  • Sovereignty (The Fortress): Total control over data boundaries and legal jurisdiction. It keeps the “digital borders” secure but often isolates you from the global innovation stream.
  • Resilience (The Hydra): The ability to survive any failure through massive, global redundancy. This requires spreading your “digital DNA” across the globe, which inherently dilutes your control.
  • Safety (The Shield): Access to world-class security and encryption protocols. Currently, the most advanced shields are forged in the R&D labs of global hyperscalers, creating a dependency that threatens the Fortress.

The “Sovereignty Trap”: Why Pure Autonomy Fails

The traditional European response has been to build “digital walls”—strict data localization and local-only provider mandates. However, this often leads to the Sovereignty Trap. By locking data into a single, local “sovereign” silo, organizations actually decrease their Resilience. A localized power failure or a targeted cyberattack on a smaller, local provider can lead to total operational paralysis. In our quest for control, we inadvertently create a single point of failure. These trade-offs highlight the complexity of achieving European Safety, Sovereignty and Resilience in the digital era.

Turning the Tide: How to Successfully Deal with the Trilemma

The winners of 2026 aren’t choosing one pillar over the others; they are redefining the relationship between them. Here is how to successfully navigate the trilemma for better European Safety, Sovereignty and Resilience.

1. Shift from “Isolation” to “Strategic Interdependence”

Stop trying to build a European clone of every US service. Instead, focus on Interoperability Layers. By using open-source standards (like Gaia-X frameworks), you can “knit together” the capability of global giants with the legal protections of local providers. You don’t need to own the whole stack to control the data that flows through it.

2. Adopt “Sovereignty-by-Design” Architectures

Don’t treat sovereignty as a legal checkbox; treat it as a technical requirement. Use Confidential Computing and Bring Your Own Key (BYOK) encryption. This allows you to use the massive processing power of global clouds (Capability) while ensuring that the provider physically cannot access your data, even under a foreign subpoena (Sovereignty).

3. Implement “Active-Active” Multi-Cloud Resilience

True resilience is no longer about having a backup; it’s about being “cloud-agnostic.” Distribute your critical workloads across a “Sovereign Cloud” for sensitive data and a global hyperscaler for high-performance tasks. If one fails, your orchestration layer shifts the load. This is Resilience without the Sacrifice of Control.

4. Leverage Public Procurement as Industrial Policy

The EU’s greatest strength is its collective buying power. By mandating “sovereign-compatible” standards in public contracts, we force global providers to adapt to our rules. We don’t just ask for safety; we define the terms of the shield.

The Path Forward: A Hybrid Future

The Digital Sovereignty Trilemma isn’t a problem to be “solved”—it’s a tension to be managed. The future belongs to the “Digital Architects” who can balance the need for global innovation with the mandate for local control.

We don’t need to build a wall around Europe. We need to build a smarter, more resilient bridge—one that is anchored in our values but reaches for the best the world has to offer. Ultimately, European Safety, Sovereignty and Resilience can only be achieved by embracing this hybrid approach.

How is your organization balancing the scales of the Digital Trilemma? Are you building walls or bridges? Let’s discuss in the comments.

#DigitalSovereignty #EUTech #DataPrivacy #CyberSecurity #Resilience #DigitalTransformation #CloudComputing #StrategicAutonomy #Insight42 #TechStrategy

Key Takeaways

  • The Digital Sovereignty Trilemma presents a challenge balancing European Safety, Sovereignty and Resilience.
  • European leaders struggle between total control, global redundancy, and access to advanced security protocols.
  • To overcome the trilemma, Europeans should shift to strategic interdependence and use interoperability layers.
  • Implementing Sovereignty-by-Design architectures can enhance data control while leveraging global cloud capabilities.
  • The future lies in balancing global innovation with local control to achieve true European Safety, Sovereignty and Resilience.
Unleash the European Bull

Microsoft Fabric: The Definitive Guide for 2026

AI In The Public Sector, Microsoft Fabric, Sovereignty Series 16th Jan 2026 Martin-Peter Lambert
Microsoft Fabric: The Definitive Guide for 2026

A complete walkthrough of architecture, governance, security, and best practices for building a unified data platform on Microsoft Fabric — written for CIOs, data architects and BI leads who need to decide, design and roll out.

A unified data platform concept for Microsoft Fabric
A unified data platform concept for Microsoft Fabric.

Key Takeaways

  • Microsoft Fabric is a unified analytics platform that aims to solve the problem of data platform sprawl by integrating various data services into a single SaaS offering.
  • OneLake is the centerpiece of Fabric, acting as a single, logical data lake for the entire organization, similar to OneDrive for data.
  • Fabric offers different “experiences” for various roles, such as data engineering, data science, and business intelligence, all built on a shared foundation.
  • The platform uses a capacity-based pricing model, which allows for scalable and predictable costs.
  • Security and governance are built-in, with features like Microsoft Purview integration, fine-grained access controls, and private links.
  • A well-defined rollout plan is crucial for a successful Fabric adoption, starting with a discovery phase, followed by a pilot, and then a full production rollout.

Who is this guide for?

This guide is for business and technical leaders who are evaluating or implementing Microsoft Fabric. It provides a comprehensive overview of the platform, from its core concepts to a practical rollout plan. Whether you are a CIO, a data architect, or a BI manager, this guide will help you understand how to leverage Fabric to build a modern, scalable, and secure data platform. For a more critical, deep technical treatment see our five-part Microsoft Fabric deep-dive series.

Why Microsoft Fabric exists (in plain language)

Most organizations don’t have a “data problem”—they have a data platform sprawl problem:

  • Multiple tools for ingestion, transformation, and reporting
  • Duplicate data copies across lakes/warehouses/marts
  • Inconsistent security rules between engines
  • A governance gap (lineage, classification, ownership)
  • Cost surprises when teams scale

Microsoft Fabric was designed to reduce that sprawl by delivering an end-to-end analytics platform as a SaaS service: ingestion → transformation → storage → real-time → science → BI, all integrated.

If your goal is a platform that business teams can trust and technical teams can scale, Fabric is fundamentally about unification: common storage, integrated experiences, shared governance, and a capacity model you can manage centrally.

What is Microsoft Fabric? (the one-paragraph definition)

Microsoft Fabric is an analytics platform that supports end-to-end data workflows—data ingestion, transformation, real-time processing, analytics, and reporting—through integrated experiences such as Data Engineering, Data Factory, Data Science, Real-Time Intelligence, Data Warehouse, Databases, and Power BI, operating over a shared compute and storage model with OneLake as the centralized data lake.

The Fabric mental model: the 6 building blocks that matter

1) OneLake = the “OneDrive for data”

OneLake is Fabric’s single logical data lake. Fabric stores items like lakehouses and warehouses in OneLake, similar to how Office stores files in OneDrive. Under the hood, OneLake is built on ADLS Gen2 concepts and supports many file types.

OneLake as a single, logical data lake for the entire organization
OneLake acts as a single, logical data lake for the entire organization.

Why this matters: OneLake is the anchor that makes “one platform” real—shared storage, consistent access patterns, fewer duplicate copies.

2) Experiences (workloads) = role-based tools on the same foundation

Fabric exposes different “experiences” depending on what you’re doing—engineering, integration, warehousing, real-time, BI—without making you stitch together separate products.

3) Items = the concrete things teams build

In Fabric, you build “items” inside workspaces (think: lakehouse, warehouse, pipelines, notebooks, eventstreams, dashboards, semantic models). OneLake stores the data behind these items.

4) Capacity = the knob you scale (and govern)

Fabric uses a capacity-based model (F SKUs). You can scale up/down dynamically and even pause capacity (pay-as-you-go model).

5) Governance = make it discoverable, trusted, compliant

Fabric includes governance and compliance capabilities to manage and protect your data estate, improve discoverability, and meet regulatory requirements.

6) Security = consistent controls across engines

Fabric has a layered permission model (workspace roles, item permissions, compute permissions, and data-plane controls like OneLake security).

Choosing the right storage: Lakehouse vs Warehouse vs “other”

This is where many Fabric projects either become elegant—or messy.

Comparison of the flexible Lakehouse and the structured Data Warehouse in Microsoft Fabric
A visual comparison of the flexible Lakehouse and the structured Data Warehouse.

Lakehouse (best when you want flexibility + Spark + open lake patterns)

Use a Lakehouse when:

  • You’re doing heavy data engineering and transformations
  • You want medallion patterns (bronze/silver/gold)
  • You’ll mix structured + semi-structured data
  • You want Spark-native developer workflows

Warehouse (best when you want SQL-first analytics and managed warehousing)

Fabric Data Warehouse is positioned as a “lake warehouse” with two warehousing items (warehouse item + SQL analytics endpoint) and includes replication to OneLake files for external access.

Real-Time Intelligence (best for streaming events, telemetry, “data in motion”)

Real-Time Intelligence is an end-to-end solution for event-driven scenarios—handling ingestion, transformation, storage, analytics, visualization, and real-time actions.

Eventstreams can ingest and route events without code and can expose Kafka endpoints for Kafka protocol connectivity.

Discovery: how to decide if Fabric is the right platform (business + technical)

Step 1 — Identify 3–5 “lighthouse” use cases

Pick use cases that prove the platform across the lifecycle:

  • Executive BI: certified metrics + governed semantic model
  • Operational analytics: near-real-time dashboards + alerts
  • Data engineering: ingestion + transformations + orchestration
  • Governance: lineage + sensitivity labeling + access controls

Step 2 — Score your current pain (and expected value)

Use a simple scoring matrix:

  • Time-to-insight (days → hours?)
  • Data trust (single source of truth?)
  • Security consistency (one model vs many?)
  • Cost predictability (capacity governance?)
  • Reuse (shared datasets and pipelines?)

Step 3 — Confirm your constraints early (these change architecture)

  • Data residency and tenant requirements (see our notes on Fabric security, GDPR and network isolation)
  • Identity model (Entra ID groups, RBAC approach)
  • Network posture (public internet vs private links)
  • Licensing & consumption model (broad internal distribution?)

The reference architecture: a unified Fabric platform that scales

Here’s a proven blueprint that works for most organizations.

5-layer reference architecture for a unified data platform in Microsoft Fabric
A 5-layer reference architecture for a unified data platform in Microsoft Fabric.

Layer 1 — Landing + ingestion

Goal: bring data in reliably, with minimal coupling.

  • Use Data Factory style ingestion/orchestration (pipelines, connectors, scheduling)
  • Land raw data into OneLake (often “Bronze”)
  • Keep ingestion contracts explicit (schemas, SLAs, source owners)

Layer 2 — Transformation (medallion pattern)

Goal: create reusable, tested datasets.

The Medallion Architecture (Bronze, Silver, Gold) for data transformation
The Medallion Architecture (Bronze, Silver, Gold) for data transformation.
  • Bronze: raw, append-only, immutable where possible
  • Silver: cleaned, conformed, deduplicated
  • Gold: curated, analytics-ready, business-friendly

Layer 3 — Serving & semantics

Goal: standardize definitions so the business stops arguing about numbers.

Gold tables feed:

  • Warehouse / SQL endpoints for SQL-first analytics
  • Power BI semantic models for governed metrics and reports (within Fabric’s unified environment)

Layer 4 — Real-time lane (optional but powerful)

Goal: detect and act on events quickly (minutes/seconds).

  • Ingest with Eventstreams
  • Store/query using Real-Time Intelligence components
  • Trigger actions with Activator (no/low-code event detection and triggers)

Layer 5 — Governance & security plane (always on)

Goal: everything is discoverable, classifiable, and controlled.

  • Microsoft Purview integration for governance
  • Fabric governance and compliance capabilities (lineage, protection, discoverability)

Security: how to build “secure by default” without slowing teams down

Understand the Fabric permission layers

Fabric uses multiple permission types (workspace roles, item permissions, compute permissions, and OneLake security) that work together.

Layered security permission model in Microsoft Fabric
A layered security permission model in Microsoft Fabric.

Practical rule:

  • Workspace roles govern “who can do what” in a workspace
  • Item permissions refine access per artifact
  • OneLake security governs data-plane access consistently

OneLake Security (fine-grained, data-plane controls)

OneLake security enables granular, role-based security on data stored in OneLake and is designed to be enforced consistently across Fabric compute engines (not per engine). Check the current feature state in Microsoft’s documentation before relying on it for production.

Network controls: private connectivity + outbound restrictions

If your organization needs tighter network posture:

  • Fabric supports Private Links at tenant and workspace levels, routing traffic through Microsoft’s private backbone.
  • You can enable workspace outbound access protection to block outbound connections by default, then allow only approved external connections (managed private endpoints or rules).

Governance & compliance capabilities

Fabric provides governance/compliance features to manage, protect, monitor, and improve discoverability of sensitive information.

A “good default” governance model:

  • Standard workspace taxonomy (by domain/product, not by team names)
  • Defined data owners + stewards
  • Certified datasets + endorsed metrics
  • Mandatory sensitivity labels for curated/gold assets (where applicable)

Capacity & licensing: the essentials (what leaders actually need to know)

Fabric uses capacity SKUs and also has important Power BI licensing implications.

Key official points from Microsoft’s pricing documentation:

  • Fabric capacity can be scaled up/down and paused (pay-as-you-go approach).
  • Power BI Pro licensing requirements extend to Fabric capacity for publishing/consuming Power BI content; however, with F64 (Premium P1 equivalent) or larger, report consumers may not require Pro licenses (per Microsoft’s licensing guidance).

How to translate this into planning decisions:

  • If your strategy includes broad internal distribution of BI content, licensing and capacity sizing should be evaluated together—not separately.
  • Treat capacity as shared infrastructure: define which workloads get priority, and put guardrails around dev/test/prod usage. We go deeper in Fabric multi-tenancy, licensing and cost control.

AI & Copilot in Fabric: what it is (and how to adopt responsibly)

Copilot in Fabric introduces generative AI experiences to help transform/analyze data and create insights, visualizations, and reports; availability varies by experience and feature state (some are preview).

Adoption best practices:

  • Enable it deliberately (not “turn it on everywhere”)
  • Create usage guidelines (data privacy, human review, approved datasets)
  • Start with low-risk scenarios (documentation, SQL drafts, exploration)

OneLake shortcuts: unify without copying (and why this changes migrations)

Shortcuts let you “virtualize” data across domains/clouds/accounts by making OneLake a single virtual data lake; Fabric engines can connect through a unified namespace, and OneLake manages permissions/credentials so you don’t have to configure each workload separately.

  • You can reduce duplicate staging copies
  • You can incrementally migrate legacy lakes/warehouses
  • You can allow teams to keep data where it is (temporarily) while centralizing governance

A practical end-to-end rollout plan (discovery → pilot → production)

Phase 1 — 2–4 weeks: Discovery & platform blueprint

Deliverables:

  • Target architecture (lakehouse/warehouse/real-time lanes)
  • Workspace strategy and naming standards
  • Security model (groups, roles, data access patterns)
  • Governance model (ownership, certification, lineage expectations)
  • Initial capacity sizing hypothesis

Phase 2 — 4–8 weeks: Pilot (“thin slice” end-to-end)

Pick one lighthouse use case and implement the full lifecycle:

  • Ingest → bronze → silver → gold
  • One governed semantic model and 2–3 business reports
  • Data quality checks + monitoring
  • Role-based access + audit-ready governance story

Success criteria (be explicit):

  • Reduced manual steps
  • Clear lineage and ownership
  • Faster cycle time for new datasets
  • A repeatable pattern others can copy

Phase 3 — 8–16 weeks: Production foundation

  • Separate dev/test/prod workspaces (or clear release flows)
  • CI/CD and deployment patterns (whatever your org standard is)
  • Cost controls: capacity scheduling, workload prioritization, usage monitoring
  • Network posture: Private Links and outbound rules if required

Phase 4 — Scale: domain rollout + self-service enablement

  • Create “golden paths” (templates for pipelines, lakehouses, semantic models)
  • Training by persona: analysts (Power BI + governance), engineers (lakehouse patterns, orchestration), ops/admins (security, capacity, monitoring)
  • Establish a data product operating model (ownership, SLAs, versioning)

Common pitfalls (and how to avoid them)

1. Treating Fabric like “just a BI tool” — Fabric is a full analytics platform; plan governance, engineering standards, and an operating model from day one.

2. Not deciding Lakehouse vs Warehouse intentionally — Use Microsoft’s decision guidance and align by workload/persona.

3. Inconsistent security between workspaces and data — Define a single permission strategy and understand how Fabric’s permission layers interact.

4. Underestimating network requirements — If your org is private-network-first, plan Private Links and outbound restrictions early.

5. Capacity without FinOps — Capacity is shared—without guardrails, “noisy neighbor” problems appear fast. Establish policies, monitoring, and environment separation.

The “done right” Fabric checklist (copy/paste)

Strategy

☐ 3–5 lighthouse use cases with measurable outcomes
☐ Target architecture and workload mapping
☐ Capacity model + distribution/licensing plan

Platform foundation

☐ Workspace taxonomy and naming standards
☐ Dev/test/prod separation
☐ CI/CD or release process defined

Data architecture

☐ Bronze/Silver/Gold pattern defined
☐ Lakehouse vs Warehouse decisions documented
☐ Real-time lane (if needed) using Eventstreams/RTI

Security & governance

☐ Permission model documented (roles, items, compute, OneLake)
☐ OneLake security strategy (where applicable)
☐ Purview governance integration approach
☐ Network posture (Private Links / outbound rules) if required

Conclusion

Microsoft Fabric represents a significant shift in the data platform landscape. By unifying the entire analytics lifecycle, from data ingestion to business intelligence, Fabric has the potential to eliminate data sprawl, simplify governance, and empower organizations to make better, faster decisions. However, a successful Fabric adoption requires careful planning, a clear understanding of its core concepts, and a phased rollout approach. By following the best practices outlined in this guide, you can unlock the full potential of Microsoft Fabric and build a data platform that is both powerful and future-proof.

Next step

Ready to start your Microsoft Fabric journey? Our Data Platforms & Analytics team designs and implements Fabric platforms with EU data residency and governance built in — contact us for an initial consultation, or read the German overview at Datenplattformen & Analytics.

References

  1. What is Microsoft Fabric – Microsoft Learn
  2. OneLake, the OneDrive for data
  3. Microsoft Fabric – Pricing
  4. Governance and compliance in Microsoft Fabric
  5. Permission model – Microsoft Fabric
  6. Decision guide: Warehouse vs Lakehouse
  7. What Is Fabric Data Warehouse?
  8. Real-Time Intelligence documentation
  9. Eventstreams overview
  10. What is Fabric Activator?
  11. Use Microsoft Purview to govern Microsoft Fabric
  12. OneLake security overview
  13. Private Links for secure access to Fabric
  14. Workspace outbound access protection
  15. Overview of Copilot in Fabric
  16. Unify data sources with OneLake shortcuts

Code Signing in Professional Software

AI In The Public Sector, Azure CAF & Cloud Migration, Resilience, Sovereignty Series 12th Jan 2026 Martin-Peter Lambert
Code Signing in Professional Software

Stop Git Impersonation, Strengthen Supply Chain Security, Meet US & EU Compliance

If you build software professionally, you don’t just need secure code—you need verifiable proof of who changed it and whether it was altered before release. Code Signing & Signed Commits play a crucial role in preventing Git impersonation and meeting US/EU compliance requirements such as NIS2, GDPR, and CRA. That’s why code signing (including Git signed commits) has become a baseline control for software supply chain security, DevSecOps, and compliance.

It also directly addresses a common risk: a developer (or attacker) committing code while pretending to be someone else. With unsigned commits, names and emails can be faked. With signed commits, identity becomes cryptographically verifiable.

This matters even more if you operate in the US and Europe, where cybersecurity requirements increasingly expect strong controls—and where the EU, in particular, attaches explicit, high penalties for non-compliance (NIS2, GDPR, and the Cyber Resilience Act). (EUR-Lex)

What is “code signing” (and what customers actually mean by it)?

In industry conversations, code signing usually means a chain of trust across your entire delivery pipeline:

  • Signed commits (Git commit signing): proves the author/committer identity for each change
  • Signed tags / signed releases: proves a release point (e.g., v2.7.0) wasn’t forged
  • Signed build artifacts: proves your binaries, containers, and packages weren’t tampered with
  • Signed provenance / attestations: proves what source + CI/CD pipeline produced the artifact (a growing expectation in supply chain security programs)

The goal is simple: integrity + identity + traceability from developer laptop to production.

Why signed commits prevent “commit impersonation”

Without signing, Git identity is just text. Anyone can set an author name/email to match a colleague and push code that looks legitimate.

Signed commits add a cryptographic signature that platforms can verify. When you enforce signed commits (especially on protected branches):

  • fake author names don’t pass verification
  • only commits signed by trusted keys are accepted
  • auditors and incident responders get a reliable attribution trail

In other words: Git commit signing is one of the cleanest ways to prevent developers (or attackers) from committing as someone else.

Code Signing = Better Security + Cleaner Audits

Customers in regulated industries (finance, critical infrastructure, healthcare, manufacturing, government vendors) frequently search for:

  • software supply chain security
  • CI/CD security controls
  • secure SDLC evidence
  • audit trail for code changes

Code signing helps because it creates durable evidence for:

  • change control (who changed what)
  • integrity (tamper-evidence)
  • accountability (strong attribution)
  • faster incident response and forensics

That’s why code signing is often positioned as a compliance accelerator: it reduces the cost and friction of proving good practices.

US Compliance View: Why Code Signing Supports Federal and Enterprise Security Requirements

In the US, the big push is secure software development and software supply chain assurance—especially for vendors selling into government and regulated sectors.

Executive Order 14028 + software attestations

Executive Order 14028 drove major follow-on guidance around supply chain security and secure software development expectations. (NIST)
OMB guidance (including updates like M-23-16) establishes timelines and expectations for collecting secure software development attestations from software producers. (The White House)
Procurement artifacts like the GSA secure software development attestation reflect this direction in practice. (gsa.gov)

NIST SSDF (SP 800-218) as the common language

Many organizations align their secure SDLC programs to the NIST Secure Software Development Framework (SSDF). (csrc.nist.gov)

Where code signing fits: it’s a practical control that supports identity, integrity, and traceability—exactly the kinds of things customers and auditors ask for when validating secure development practices.

(In the US, the “penalty” is often commercial: failed vendor security reviews, procurement blockers, contract risk, and higher liability after an incident—especially if your controls can’t be evidenced.)

EU Compliance View: NIS2, GDPR, and the Cyber Resilience Act (CRA) Penalties

Europe is where penalties become very concrete—and where customers increasingly ask vendors about NIS2 compliance, GDPR security, and Cyber Resilience Act compliance.

NIS2 penalties (explicit fines)

NIS2 includes an administrative fine framework that can reach:

  • Essential entities: up to €10,000,000 or 2% of worldwide annual turnover (whichever is higher)
  • Important entities: up to €7,000,000 or 1.4% of worldwide annual turnover (whichever is higher) (EUR-Lex)

Why code signing matters for NIS2 readiness: it supports strong controls around integrity, accountability, and change management—key building blocks for cybersecurity governance in professional environments.

GDPR penalties (security failures can get expensive fast)

GDPR allows administrative fines up to €20,000,000 or 4% of global annual turnover (whichever is higher) for certain serious infringements. (GDPR)

Code signing doesn’t “solve GDPR,” but it reduces the risk of supply-chain compromise and improves your ability to demonstrate security controls and traceability after an incident.

Cyber Resilience Act (CRA) penalties + timelines

The CRA (Regulation (EU) 2024/2847) introduces horizontal cybersecurity requirements for products with digital elements. Its penalty article states that certain non-compliance can be fined up to:

  • €15,000,000 or 2.5% worldwide annual turnover (whichever is higher), and other tiers including
  • €10,000,000 or 2%, and €5,000,000 or 1% depending on the type of breach. (EUR-Lex)

Timing also matters: the CRA applies from 11 December 2027, with earlier dates for specific obligations (e.g., some reporting obligations from 11 September 2026 and some provisions from 11 June 2026). (EUR-Lex)

For vendors, this translates into a customer question you should expect to hear more often:

“How do you prove the integrity and origin of what you ship?”

Your best answer includes code signing + signed releases + signed artifacts + verifiable provenance.

Implementation Checklist: Code Signing Best Practices (Practical + Auditable)

If you want code signing that actually holds up in audits and real incidents, implement it as a system—not a developer “nice-to-have”.

1) Enforce Git signed commits

  • Require signed commits on protected branches (main, release/*)
  • Block merges if commits are not verified
  • Require signed tags for releases

2) Secure developer signing keys

  • Prefer hardware-backed keys (or secure enclaves)
  • Require MFA/SSO on developer accounts
  • Rotate keys and remove trust when people change roles or leave

3) Sign what you ship (artifact signing)

  • Sign containers, packages, and binaries
  • Verify signatures in CI/CD and at deploy time

4) Add provenance (supply chain proof)

  • Produce build attestations/provenance so you can prove which pipeline built which artifact from which source

Is Git commit signing the same as code signing?
Git commit signing proves identity and integrity at the source-control level. Code signing often also includes release and artifact signing for what you ship.

Does signed commits stop a compromised developer laptop?
It helps with attribution and tamper-evidence, but you still need endpoint security, key protection, least privilege, reviews, and CI/CD hardening.

What’s the business value?
Less impersonation risk, stronger software supply chain security, faster audits, clearer incident response, and a better compliance posture for US and EU customers.

Takeaway

If you sell software into regulated or security-sensitive markets, code signing and signed commits are no longer optional. They directly prevent commit impersonation, strengthen software supply chain security, and support compliance conversations—especially in the EU where NIS2, GDPR, and CRA penalties can be severe. (EUR-Lex)

If you want, I can also provide:

  • an SEO-focused FAQ expansion (10–15 more questions),
  • a one-page “Code Signing Policy” template,
  • or platform-specific enforcement steps (GitHub / GitLab / Azure DevOps / Bitbucket) written in a customer-friendly way.

#CodeSigning #SignedCommits #GitSecurity #SoftwareSupplyChain #SupplyChainSecurity #DevSecOps #SecureSDLC #CICDSecurity #NIS2 #GDPR #CyberResilienceAct #Compliance #RegTech #RiskManagement #CybersecurityGovernance #SoftwareIntegrity #CodeIntegrity #IdentitySecurity #NonRepudiation #ZeroTrust #SecurityControls #ChangeManagement #GitHubSecurity #GitLabSecurity #SBOM #SLSA #SoftwareProvenance #ArtifactSigning #ReleaseSigning #EnterpriseSecurity #CloudSecurity #SecurityLeadership #CISO #SecurityEngineering #ProductSecurity #SecurityCompliance

The Monopoly of Progress

AI In The Public Sector, Growth, Resilience, Sovereignty Series 3rd Jan 2026 Martin-Peter Lambert
The Monopoly of Progress

Why Abundance, Security, and Free Markets are the Only True Catalysts for Innovation

Introduction: The Paradox of Creation

In the modern economic narrative, competition is lionized as the engine of progress. We are taught that a fierce marketplace, where rivals battle for supremacy, drives innovation, lowers prices, and ultimately benefits society. However, a closer examination of the last three decades of technological advancement reveals a startling paradox: true, transformative innovation—the kind that leaps from zero to one—rarely emerges from the bloody trenches of perfect competition. This notion supports the idea that perfect competition stifles progress and creativity, leading us to question why abundance, security, and free markets are the only true catalysts for innovation, as these environments often look far more like a monopoly with long-term vision rather than a cutthroat market.

This thesis, most forcefully articulated by entrepreneur and investor Peter Thiel in his seminal work, Zero to One, argues that progress is not a product of incremental improvements in a crowded field, but of bold new creations that establish temporary monopolies [1]. This article will explore Thiel’s framework, arguing that the capacity for radical innovation is contingent upon the financial security and long-term planning horizons that only sustained profitability can provide.

The Two Types of Progress

We will then turn our lens to the European Union, particularly Germany, to diagnose why the continent has failed to produce world-dominating technology companies in recent decades, attributing this failure to a culture of short-termism, stifling regulation, and punitive taxation.

Finally, we will dismantle the notion that the state can act as an effective substitute for the market in allocating capital for innovation. Drawing on the work of Nobel Prize-winning economists like Friedrich Hayek and the laureates recognized for their work on creative destruction, we will demonstrate that centralized planning is, and has always been, the most inefficient allocator of resources, fundamentally at odds with the chaotic, decentralized, and often wasteful process that defines true invention.

The Thiel Doctrine: Competition is for Losers

Peter Thiel’s provocative assertion that “competition is for losers” is not an endorsement of anti-competitive practices but a fundamental critique of how we perceive value creation. He draws a sharp distinction between “0 to 1” innovation, which involves creating something entirely new, and “1 to n” innovation, which consists of copying or iterating on existing models. While globalization represents the latter, spreading existing technologies and ideas, true progress is defined by the former.

To understand this, Thiel contrasts two economic models: perfect competition and monopoly.

The Innovation Paradox: Competition vs Monopoly

In a state of perfect competition, no company makes an economic profit in the long run. Firms are undifferentiated, selling at whatever price the market dictates. If there is money to be made, new firms enter, supply increases, prices fall, and the profit is competed away. In this brutal struggle for survival, companies are forced into a short-term, defensive crouch. Their focus is on marginal gains and cost-cutting, not on ambitious, long-term research and development projects that may not pay off for years, if ever [1].

The U.S. airline industry serves as a prime example. Despite creating immense value by transporting millions of passengers, the industry’s intense competition drives profits to near zero. In 2012, for instance, the average airfare was $178, yet the airlines made only 37 cents per passenger trip [1]. This leaves no room for the “waste” and “slack” necessary for bold experimentation.

In stark contrast, a company that achieves a monopoly—not through illegal means, but by creating a product or service so unique and superior that it has no close substitute—can generate sustained profits. These profits are not a sign of market failure but a reward for creating something new and valuable. Google, for example, established a monopoly in search in the early 2000s. Its resulting profitability allowed it to invest in ambitious “moonshot” projects like self-driving cars and artificial intelligence, endeavors that a company struggling for survival could never contemplate.

This environment of abundance and security is the fertile ground from which “Zero to One” innovations spring. It allows a company to think beyond immediate survival and plan for a decade or more into the future, accepting the necessity of financial
waste and the high probability of failure in the pursuit of groundbreaking discoveries. This is the core of the Thiel doctrine: progress requires the security that only a monopoly, however temporary, can provide.

The European Malaise: A Continent of Incrementalism

For the past three decades, a glaring question has haunted the economic landscape: where are Europe’s Googles, Amazons, or Apples? Despite a highly educated workforce, strong industrial base, and significant government investment in R&D, the European Union, and Germany in particular, has failed to produce a single technology company that dominates its global market. The continent’s tech scene is characterized by a plethora of “hidden champions”—highly successful, niche-focused SMEs—but it lacks the breakout, world-shaping giants that have defined the digital age. This is not an accident of history but a direct consequence of a political and economic culture that is fundamentally hostile to the principles of “Zero to One” innovation.

The Triple Constraint: Regulation, Taxation, and Short-Termism

The European innovation deficit can be attributed to a trifecta of self-imposed constraints:

EU Innovation Triple Constraint
  1. A Culture of Precautionary Regulation: The EU’s regulatory philosophy is governed by the “precautionary principle,” which prioritizes risk avoidance over seizing opportunities. This manifests in sprawling, complex regulations like the General Data Protection Regulation (GDPR) and the AI Act. While well-intentioned, these frameworks impose immense compliance burdens, especially on startups and smaller firms. A 2021 study found that GDPR led to a measurable decline in venture capital investment and reduced firm profitability and innovation output, as resources were diverted from R&D to legal and compliance departments [2]. The AI Act, with its risk-based categories and strict mandates, creates further bureaucratic hurdles that stifle the rapid, iterative experimentation necessary for AI development. This risk-averse environment encourages incremental improvements within established paradigms rather than the disruptive breakthroughs that challenge them.
  2. Punitive Taxation and the Demand for Premature Profitability: European tax policies, particularly in countries like Germany where the average corporate tax burden is around 30%, create a significant disadvantage for innovation-focused companies [3]. High taxes on corporate profits and wealth disincentivize the long-term, high-risk investments that drive transformative innovation. Furthermore, the European venture capital ecosystem is less developed and more risk-averse than its U.S. counterpart. Startups often rely on bank lending, which demands a clear and rapid path to profitability. This pressure to become profitable quickly is antithetical to the “wasteful” and often decade-long process of developing truly novel technologies. As a result, many of Europe’s most promising startups, such as UiPath and Dataiku, have relocated to the U.S. to access larger markets, deeper capital pools, and a more favorable regulatory environment [2].
  3. A Fragmented Market: Despite the ideal of a single market, the EU remains a patchwork of 27 different national laws and regulatory interpretations. This fragmentation prevents European companies from achieving the scale necessary to compete with their American and Chinese rivals. A startup in one member state may face entirely different compliance requirements in another, creating significant barriers to expansion. This stands in stark contrast to the unified markets of the U.S. and China, where companies can scale rapidly to achieve national and then global dominance.

This combination of overregulation, high taxation, and market fragmentation creates an environment where it is nearly impossible for companies to achieve the sustained profitability and security necessary for “Zero to One” innovation. The European model, in essence, enforces a state of perfect competition, trapping its companies in a cycle of incrementalism and ensuring that the next generation of technological giants will be born elsewhere.

The State as Innovator: A Proven Failure

Faced with this innovation deficit, some policymakers in Europe and elsewhere have been tempted by the siren song of industrial planning.

Capital Allocation: The Knowledge Problem

The argument is that the state, with its vast resources and ability to direct investment, can strategically guide innovation and pick winners. This is a dangerous and historically discredited idea. The 2025 Nobel Prize in Economics, awarded to Philippe Aghion, Peter Howitt, and Joel Mokyr for their work on innovation-led growth, serves as a powerful reminder that prosperity comes not from stability and central planning, but from the chaotic and unpredictable process of “creative destruction” [4].

The Knowledge Problem and the Price System

Nobel laureate Friedrich Hayek, in his seminal work, dismantled the socialist belief that a central authority could ever effectively direct an economy. He argued that the knowledge required for rational economic planning is not concentrated in a single mind or committee but is dispersed among millions of individuals, each with their own unique understanding of their particular circumstances. The market, through the price system, acts as a vast, decentralized information-processing mechanism, coordinating the actions of these individuals without any central direction [5].

As Hayek wrote, “The economic problem of society is thus not merely a problem of how to allocate ‘given’ resources—if ‘given’ is taken to mean given to a single mind which could solve the problem set by these ‘data.’ It is rather a problem of how to secure the best use of resources known to any of the members of society, for ends whose relative importance only these individuals know” [5].

State-led innovation initiatives inevitably fail because they are blind to this dispersed knowledge. A government committee, no matter how well-informed, cannot possibly possess the information necessary to make the millions of interconnected decisions required to bring a new technology to market. The historical record is littered with the failures of central planning, from the economic collapse of the Soviet Union to the stagnation of countless state-owned enterprises.

Creative Destruction: The Engine of Progress

The work of the 2025 Nobel laureates reinforces Hayek’s critique. Joel Mokyr’s historical analysis of the Industrial Revolution reveals that it was not the product of government programs but of a cultural shift towards open inquiry, merit-based debate, and the free exchange of ideas. The political fragmentation of Europe, which allowed innovators to flee repressive regimes, was a key factor in this process [4].

Aghion and Howitt’s model of “growth through creative destruction” shows that a dynamic economy depends on a constant process of experimentation, entry, and replacement. New, innovative firms challenge and displace established ones, driving progress. This process is inherently messy and unpredictable. It cannot be “engineered” or “guided” by a central planner. Attempts to protect incumbents or strategically direct innovation only serve to entrench mediocrity and stifle the very dynamism that drives growth.

Policies like Europe’s employment protection laws, which make it difficult and expensive to restructure or downsize a failing venture, work directly against this process. A dynamic economy requires that entrepreneurs be free to enter the market, fail, and try again without asking for the state’s permission or being cushioned from the consequences of failure.

The Market at Work: Three Stories of Innovation and Regulation

To make the abstract principles of market dynamics and regulatory friction concrete, consider three powerful stories of technologies that share common roots but followed radically different cost trajectories. These case studies vividly illustrate how free, competitive markets drive costs down and quality up, while regulated, third-party-payer systems often achieve the opposite.

Story 1: LASIK—A Clear View of the Free Market

LASIK eye surgery is a modern medical miracle, yet it operates almost entirely outside the conventional health insurance system. As an elective procedure, it is a cash-pay service where consumers act as true customers, shopping for the best value. The results are a textbook example of free-market success. In the late 1990s, the procedure cost around $2,000 per eye in today’s dollars. A quarter-century later, the price has not only failed to rise with medical inflation but has actually fallen in real terms, with the average cost remaining around $1,500-$2,500 per eye [6].

More importantly, the quality has soared. Today’s all-laser, topography-guided custom LASIK is orders of magnitude safer, more precise, and more effective than the original microkeratome blade-based procedures. This combination of falling prices and rising quality is what we expect from every other technology sector, from televisions to smartphones. It happens in LASIK for one simple reason: providers compete directly for customers who are spending their own money. There are no insurance middlemen, no complex billing codes, and no government price controls to distort the market. The result is relentless innovation and price discipline.

Story 2: The Genome Revolution—Faster Than Moore’s Law

The most stunning example of technology-driven cost reduction in human history is not in computing, but in genomics. When the Human Genome Project was completed in 2003, the cost to sequence a single human genome was nearly $100 million. By 2008, with the advent of next-generation sequencing, that cost had fallen to around $10 million. Then, something incredible happened. The cost began to plummet at a rate that far outpaced Moore’s Law, the famous benchmark for progress in computing. By 2014, the coveted “$1,000 genome” was a reality. Today, a human genome can be sequenced for as little as $200 [7].

This 99.9998% cost reduction occurred in a field driven by fierce technological competition between companies like Illumina, Pacific Biosciences, and Oxford Nanopore. It was a race to innovate, fueled by research and consumer demand, largely unencumbered by the regulatory thicket of the traditional medical device market. While the interpretation of genomic data for clinical diagnosis is regulated, the underlying technology of sequencing itself has been free to follow the logic of the market, delivering exponential gains at an ever-lower cost.

Story 3: The Insulin Tragedy—A Century of Regulatory Failure

In stark contrast to LASIK and genomics stands the story of insulin, a life-saving drug discovered over a century ago. The basic technology for producing insulin is well-established and inexpensive; a vial costs between $3 and $10 to manufacture. Yet, in the heavily regulated U.S. healthcare market, the price has become a national scandal. The list price of Humalog, a common insulin analog, skyrocketed from $21 a vial in 1996 to over $332 in 2019—a more than 1,500% increase [8].

How is this possible? The answer lies in a web of regulatory capture and market distortion. The U.S. patent system allows for “evergreening,” where minor tweaks to delivery devices or formulations extend monopolies. The FDA’s classification of insulin as a “biologic” has historically made it nearly impossible for cheaper generics to enter the market. Most critically, a shadowy ecosystem of Pharmacy Benefit Managers (PBMs) negotiates secret rebates with manufacturers, creating perverse incentives to favor high-list-price drugs. The FTC even sued several PBMs in 2024 for artificially inflating insulin prices [9]. In this system, the consumer is not the customer; the PBM is. The result is a market where a century-old, life-saving technology has become a luxury good, a tragic testament to the failure of a market that is anything but free.

These three stories—of sight, of self-knowledge, and of survival—tell a single, coherent tale. Where markets are free, transparent, and competitive, innovation flourishes and costs fall. Where they are burdened by regulation, obscured by middlemen, and captured by entrenched interests, the consumer pays the price, both literally and figuratively.

Conclusion: Embracing the Monopoly of Progress

The evidence is clear we have a conundrum: true, transformative innovation is not a product of competition alone but in its’ results – not in ensuring same suboptimal outcome by regulated process. It requires an environment of abundance and security where companies can afford to think long-term, embrace risk, and invest in the “wasteful” process of discovery. Peter Thiel’s framework, far from being a defense of predatory monopolies, is a call to recognize the conditions necessary for human progress.

The failure of the EU and Germany to produce world-leading technology companies is a direct result of their hostility to these conditions. A culture of precautionary regulation, punitive taxation, and short-term profitability has created a continent of incrementalism (keep it the same – if not, we cannot deal with setbacks), where the fear of failure outweighs the ambition to create something new. The temptation to solve this problem through state-led industrial planning is a dangerous illusion that ignores the fundamental lessons of economic history.

If we are to unlock the next wave of human progress, we must abandon the comforting but false narrative of perfect competition and embrace the messy, unpredictable, and often monopolistic reality of innovation. This means creating an ecosystem that rewards bold bets and tolerates failure. It means light regulation, competitive taxation, and a culture that celebrates the entrepreneur, not the bureaucrat. The path to a better future is not paved with the good intentions of central planners but with the creative destruction of the free market. It is a path that leads, paradoxically, through the monopoly of progress.

In essence – we need the right balance. The EU has the most potential to maximize output by a minimal input! The US has to catch up on food safety and non capitalistic and predatory capitalism.
We all can learn something from each other – including not mentioned global super powers!

#Insight42 #PublicSectorInnovation #DigitalSovereignty #ZeroToOne #ThielDoctrine #GovTech #DigitalTransformation #GermanyDigital #EUTech #InnovationStrategy #PublicProcurement #SovereignTech #RegulatoryReform #CreativeDestruction #EconomicGrowth #DigitalDecade #SmartGovernment #PublicAdmin #TechPolicy #FutureOfGovernment

References

[1] Peter Thiel, “Competition is for Losers,” Wall Street Journal, September 12, 2014

[9] Federal Trade Commission, “FTC Sues Prescription Drug Middlemen for Artificially Inflating Insulin Drug Prices,” September 20, 2024

Related Topics:
https://insight42.com/unleash-the-european-bull/

Public Sector AI, Part 3: The Procurement Playbook — Fast, Secure, Sovereign

AI In The Public Sector 28th Dec 2025 Martin-Peter Lambert
Public Sector AI, Part 3: The Procurement Playbook — Fast, Secure, Sovereign

A 3-part series on AI procurement for government digital transformation. Part 3 of 3 — see Part 1: The Revolution Will Be Sovereign and Part 2: Agile vs. Goliath.

The public sector AI procurement playbook: fast, secure, sovereign

Welcome to the final instalment of our AI procurement guide for the public sector. In Part 1, we established the critical importance of sovereign AI. In Part 2, we presented the data showing why agile, smaller vendors consistently outperform large tech intermediaries in public sector AI implementation.

Now, let’s translate these insights into a practical, actionable playbook. How do you, a public sector leader, avoid the 95% failure rate and build a government AI strategy that is fast, secure, and truly serves your citizens? This is your step-by-step guide.

The Four-Step Playbook for Sovereign AI Procurement

This isn’t about boiling the ocean or launching a massive, multi-year overhaul. It’s about making smart, strategic moves that build momentum and deliver measurable value. The SAP paper put it perfectly: start with the “low-hanging fruit” [1].

Step 1: Target Back-Office Bottlenecks for High-ROI Automation

Forget the flashy, headline-grabbing AI chatbot for now. The MIT report was unequivocal: the biggest and fastest ROI comes from public sector automation in the back office [2]. Begin by identifying your most tedious, repetitive, and resource-intensive internal processes.

Back-office automation as the starting point for public sector AI

Prime candidates include:

  • Data entry and migration
  • Document processing and classification
  • Internal helpdesk and IT support tickets
  • Invoice processing and financial reconciliation
  • Scheduling and resource allocation

These projects are the ideal starting point for your government AI adoption journey because they are low-risk, high-impact, and the gains are easy to measure. You’re not just saving money; you’re freeing up your talented public servants to focus on the high-value, citizen-facing work they were hired to do. This approach builds confidence, demonstrates the practical power of AI to internal sceptics, and creates the momentum needed for more ambitious projects — exactly the logic behind our Agentic AI Readiness-Workshop.

Step 2: Buy, Don’t Build: A Core Tenet of Agile AI Procurement

The data is conclusive. Organisations that purchase specialised AI tools from expert vendors see a 67% success rate, while those that attempt to build everything in-house fail two-thirds of the time [2]. The impulse to build a proprietary system is strong in government, but it’s a trap. You will burn through your budget and political capital reinventing the wheel.

Instead, embrace agile AI procurement by partnering with the Davids. Find the domestic, specialised companies that have already built proven solutions for your specific pain points. Your AI vendor selection criteria should prioritise:

What to Look ForWhy It Matters for Public Sector AI Procurement
Open-weight modelsPrevents vendor lock-in; allows for customisation and inspection.
InteroperabilityIntegrates with your existing systems; avoids creating new data silos.
Local data residencyEnsures compliance with GDPR and national data protection laws.
Transparent pricingAvoids hidden fees and escalating costs as you scale.
Proven track recordDemand case studies and references within the public sector.

This is your best defence against AI vendor lock-in. As the McKinsey report on European AI sovereignty argues, the goal is to create a “single market for AI” built on open standards and partnerships, not isolated fortresses [3].

Step 3: Empower Your Frontline Managers to Drive Adoption

A common mistake in large organisations is centralising all AI expertise in a remote “innovation lab” that is disconnected from day-to-day operational realities. This creates a chasm between the people building AI solutions and the people who actually need them.

A successful government AI strategy takes the opposite approach: it empowers frontline managers to drive adoption from the ground up [2].

Your department heads and team leads know where the real problems are. Give them the budget and authority to find and implement AI tools that solve their teams’ specific challenges. This decentralised approach fosters a culture of innovation and ensures that AI is adopted in a way that is practical, relevant, and immediately useful.

Step 4: Use Your Procurement Power to Anchor the Sovereign AI Ecosystem

Here’s a secret weapon that public sector leaders often overlook: you are a massive market maker.

Public procurement as a catalyst for a sovereign AI ecosystem
Strategic procurement can act as a powerful catalyst, nurturing a thriving local ecosystem of agile and sovereign AI innovators.

Government procurement is one of the largest sources of demand in any economy. When you choose to buy a product or service, you’re not just solving your own problem; you’re sending a powerful signal to the market. You’re telling innovators, “This is what we need. Build more of this.”

McKinsey suggests that European governments could earmark at least 10% of their digital transformation budgets for sovereign AI solutions [3]. This creates the stable, anchor demand that allows smaller, domestic AI companies to scale and compete with global giants.

By consciously choosing to partner with local innovators, you are not just solving your own problems; you are building a robust, sovereign AI ecosystem in your own backyard.

The Future of Government is Agile

The digital transformation of government is not primarily a technical challenge; it’s a strategic one. It’s about resisting the siren song of the big intermediaries and making a conscious choice to be agile, independent, and sovereign.

By focusing on practical problems, partnering with specialised innovators, empowering your people, and using your procurement power strategically, you can build an AI-powered public sector that is more efficient, more responsive, and more resilient.

Summary: The Insight42 AI Procurement Checklist

StepActionKey Metric
1Target back-office bottlenecks for automationHours saved per week
2Buy specialised tools from agile, sovereign partners67% success rate vs. 22% for internal builds
3Empower frontline managers to drive adoptionNumber of use cases identified by teams
4Use procurement power to support local AI ecosystem% of AI budget spent on sovereign solutions

Thank you for reading this series. If you’re ready to take the next step in your public sector AI procurement journey, Insight42 is here to help — see our Agentic AI Beratung (German), Souveräne Cloud Beratung for the infrastructure side, or contact us.

References

  1. Public Sector Network & SAP. “AI in the Public Sector.” 2025.
  2. Estrada, Sheryl. “MIT report: 95% of generative AI pilots at companies are failing.” Fortune, August 18, 2025.
  3. McKinsey & Company. “Accelerating Europe’s AI adoption: The role of sovereign AI capabilities.” December 19, 2025.

Public Sector AI, Part 2: Agile vs. Goliath in Government AI — A Procurement Guide

AI In The Public Sector 26th Dec 2025 Martin-Peter Lambert
Public Sector AI, Part 2: Agile vs. Goliath in Government AI — A Procurement Guide

A 3-part series on AI procurement for government digital transformation. Part 2 of 3 — see Part 1: The Revolution Will Be Sovereign and Part 3: The Procurement Playbook.

Innovation vs. bureaucracy: the battle for the future of government AI
The battle for the future of government AI isn’t about budget; it’s about bureaucracy vs. innovation.

In Part 1 of our guide, we established a new imperative for AI in the public sector: the future is sovereign. We highlighted the risks of AI vendor lock-in and the need for a government AI strategy that prioritises data control and independence.

Now, let’s examine the data that should change how every public procurement officer approaches government AI procurement. We will explore why the lumbering Goliaths of the tech world, despite their vast resources, are being consistently outmanoeuvred by the nimble Davids of the innovation ecosystem.

The 95% Failure Rate: A Tale of Two AI Implementation Strategies

Here is a statistic that should be central to every public sector AI implementation plan: a recent MIT report found that 95% of enterprise generative AI pilots fail to deliver any return on investment [1].

95% of enterprise AI pilots fail to deliver ROI (MIT report)
Data from MIT shows a 95% failure rate for enterprise AI pilots — a clear warning for public sector procurement.

Let that sink in.

Nineteen out of every twenty large-scale AI projects are stuck in “pilot purgatory,” consuming millions in public funds with no measurable impact. The MIT report, based on extensive research including 150 leadership interviews and 300 public AI deployment analyses, identifies the root cause not as a failure of technology, but as a failure of strategy. Large organisations are attempting to build complex, monolithic tools from scratch, getting bogged down in internal bureaucracy, and misallocating resources on cosmetic front-end projects instead of focusing on high-ROI public sector automation in the back office.

As the lead author of the MIT report noted:

“Almost everywhere we went, enterprises were trying to build their own tool… but the data showed purchased solutions delivered more reliable results.”

Aditya Challapally, MIT NANDA Initiative [1]

Now, contrast this with the small business sector. A recent survey featured in the Los Angeles Times found that 92% of small businesses have already integrated AI into their operations—a massive leap from just 20% in 2023 [2]. They are, according to the report, “operationalizing it faster and more pragmatically than many large enterprises.”

The Tale of the Tape: A Clear Choice for AI Vendor Selection

This head-to-head comparison provides a clear framework for AI vendor selection in government:

MetricLarge Enterprises (The Goliaths)Small & Medium Businesses (The Davids)
AI Pilot Success Rate5% deliver ROI [1]92% have integrated AI [2]
Primary ApproachBuild complex, internal toolsBuy specialised, proven solutions
Key ObstacleInternal bureaucracy, flawed integrationLimited resources (overcome by agility)
Typical Outcome“Pilot Purgatory”Rapid, pragmatic operationalisation
Success with Purchased Tools67% [1]High (default approach)
Success with Internal Builds~22% [1]N/A

This data reveals a clear pattern. The Goliaths are trapped by their own scale. Their size, once a strength, has become a liability. They are intermediaries caught in their own interests, while the Davids are on the front lines, directly connected to the source of innovation and laser-focused on solving real-world problems. This makes a compelling case for agile AI procurement.

The Agility Advantage: From Concept to Nationwide Deployment in Three Weeks

Agility vs. bureaucracy in government procurement
Agile partners can deliver solutions in weeks, while large enterprises can be stuck in bureaucratic red tape for years.

Need proof that agility trumps scale in public sector AI implementation? Look no further than the case study in the SAP document that inspired this series.

When the pandemic hit Germany, the city of Hamburg needed to distribute aid to struggling artists—fast. Did they enter a multi-year procurement cycle with a tech behemoth? No. They partnered with an agile team and launched a fully functional aid-application platform in just three weeks—and then rolled it out across all 16 German states [3].

Three weeks. That is the agility advantage in action.

Small, domestic partners who understand the local regulatory landscape can move at the speed of need. They are not bogged down by layers of management or a product roadmap set years in advance by a committee on another continent. They are built to be responsive, to iterate quickly, and to deliver value—not just billable hours.

The European Renaissance and Open-Source AI

This trend is accelerating across Europe. While US giants focus on closed, proprietary models that lead to AI vendor lock-in, France’s Mistral AI has become a European champion by releasing powerful, open-weight models that offer developers greater control and transparency [4]. In June 2025, Mistral launched Europe’s first AI reasoning model, proving that you don’t need to be a trillion-dollar company to lead in AI innovation [5].

This highlights the core advantages of partnering with smaller, specialised vendors:

  1. Direct Connection to the Source: Small innovators are the source of the technology, not just resellers.
  2. Domestic Agility: They understand local regulations like GDPR and the EU AI Act, and can move quickly.
  3. Aligned Incentives: Their success depends on delivering real value to you, not on maximising contract size.

The Clear Choice for Your Next Procurement Cycle

The choice for public sector leaders is clear. Do you bet on the Goliath, with their 95% failure rate and lock-in contracts? Or do you embrace agile AI procurement and partner with the Davids—the sovereign, innovative companies that are actually getting the job done?

In our final post, we provide a practical playbook for making that transition: how to choose the right partners, where to focus your efforts, and how to build a fast, secure, and sovereign AI future for your organisation.

Continue reading: Part 3: The Public Sector AI Procurement Playbook — Fast, Secure, Sovereign
Previous: Part 1: A Guide to Sovereign AI in the Public Sector

References

  1. Estrada, Sheryl. “MIT report: 95% of generative AI pilots at companies are failing.” Fortune, August 18, 2025.
  2. Williams, Paul. “AI for Small Business: 92% Adoption Rate Drives Growth.” Los Angeles Times, December 14, 2025.
  3. Public Sector Network & SAP. “AI in the Public Sector.” 2025.
  4. Open Source Initiative. “Open Source and the future of European AI sovereignty.” June 18, 2025.
  5. Reuters. “France’s Mistral launches Europe’s first AI reasoning model.” June 10, 2025.

Insight42 provides expert guidance for public sector organisations navigating the AI transition — fast, secure and sovereign. See our Agentic AI Beratung (German) or Agentic AI Solutions.

Unleash the European Bull

AI In The Public Sector, Resilience, Sovereignty Series 24th Dec 2025 Martin-Peter Lambert
Unleash the European Bull

Unleashing Innovation in the Age of Integrated Platforms – and Rediscovery of Free Discovery!

In the global arena of technological dominance, the United States soars as the Eagle, Russia stands as the formidable Bear, and China commands as the mythical Dragon. The European Union, with its rich history of innovation and immense economic power, is the Bull—a symbol of strength and potential, yet currently tethered by its own well-intentioned constraints. This post explores how the EU can unleash its inherent creativity and forge a new path to digital sovereignty, not by abandoning its principles, but by embracing a new model of innovation inspired by the very giants it seeks to rival.

The Palantir Paradigm: Integration as the New Frontier

At the heart of the modern software landscape lies a powerful paradigm, exemplified by companies like Palantir. Their genius is not in reinventing the wheel, but in masterfully integrating existing, high-quality open-source components into a single, seamless platform. Technologies like Apache Spark, Kubernetes, and various open-source databases are the building blocks, but the true value—and the competitive advantage—lies in the proprietary integration layer that connects them.

Palantir Integration Model

This integrated approach creates a powerful synergy, transforming a collection of disparate tools into a cohesive, intelligent system. It’s a model that delivers immense value to users, who are shielded from the underlying complexity and can focus on solving their business problems. This is the new frontier of software innovation: not just creating new components, but artfully combining existing ones to create something far greater than the sum of its parts.

In contrast, the European tech landscape, while boasting a wealth of world-class open-source projects and brilliant developers, remains fragmented. It’s a collection of individual gems that have yet to be set into a crown.

Fragmented EU Landscape

The European Paradox: Drowning in Regulation, Starving for Innovation

The legendary management consultant Peter Drucker famously stated, “Business has only two functions — marketing and innovation.” He argued that these two functions produce results, while all other activities are simply costs. This profound insight cuts to the heart of the European paradox. The EU’s commitment to data privacy and ethical technology is laudable, but its current regulatory approach has created a system where it excels at managing costs (regulation) rather than producing results (innovation).

Regulations like the GDPR and the AI Act, while designed to protect citizens, have inadvertently erected barriers to innovation, particularly for the small and medium-sized enterprises (SMEs) that are the lifeblood of the European economy. When a continent is more focused on perfecting regulation than fostering innovation, it finds itself in an untenable position: it can only market products that it does not have.

This “one-size-fits-all” regulatory framework creates a natural imbalance. Large, non-EU tech giants have the vast resources and legal teams to navigate the complex compliance landscape, effectively turning regulation into a competitive moat. Meanwhile, European startups and SMEs are forced to divert precious resources from innovation to compliance, stifling their growth and ability to compete on a global scale.

Regulatory Imbalance

This is the European paradox: a continent rich in talent and technology, yet constrained by a system that favors established giants over homegrown innovators. The result is a landscape where the EU excels at creating rules but struggles to create world-beating products. To get back to innovation, Europe must shift its focus from simply regulating to actively enabling the creation of new technologies.

Unleashing the Bull: A New Path for European Tech Sovereignty

To break free from this paradox, the EU must forge a new path—one that balances its regulatory ideals with the pragmatic need for innovation. The solution lies in the creation of secure innovation zones, or regulatory sandboxes. These are controlled environments where startups and developers can experiment, build, and iterate rapidly, free from the immediate weight of full regulatory compliance.

Innovation Pathway

This approach is not about abandoning regulation, but about applying it at the right stage of the innovation lifecycle. It’s about prioritizing potential benefits and viability first, allowing new ideas to flourish before subjecting them to the full force of regulatory scrutiny. By creating these safe harbors for innovation, the EU can empower its brightest minds to build the integrated platforms of the future, turning its fragmented open-source landscape into a cohesive, competitive advantage.

The Vision: A Sovereign and Innovative Europe

Imagine a future where the European Bull is unleashed. A future where a vibrant ecosystem of homegrown tech companies thrives, building on the continent’s rich open-source heritage to create innovative, integrated platforms. A future where the EU is not just a regulator, but a leading force in the global technology landscape.

The European Bull Unleashed

This vision is within reach. The EU has the talent, the technology, and the values to build a digital future that is both innovative and humane. By embracing a new model of innovation—one that fosters experimentation, prioritizes integration, and applies regulation with wisdom and foresight—the European Bull can take its rightful place as a global leader in the digital age.

References

[1] Palantir and Open-Source Software
[2] Open source software strategy – European Commission
[3] New Study Finds EU Digital Regulations Cost U.S. Companies Up To $97.6 Billion Annually
[4] EU AI Act takes effect, and startups push back. Here’s what you need to know

#DigitalSovereignty #EUTech #DigitalTransformation #Innovation #Technology #EuropeanUnion #DigitalEurope #TechPolicy #OpenSource #PlatformIntegration #CloudSovereignty #DataSovereignty #EnterpriseArchitecture #DigitalStrategy #TechInnovation #EUInnovation #EUProcurement #PublicSector #DigitalAutonomy #TechConsulting #AIAct #GDPR #RegulatoryInnovation #EuropeanTech

Public Sector AI, Part 1: A Guide to Sovereign AI — The Revolution Will Be Sovereign

AI In The Public Sector 23rd Dec 2025 Martin-Peter Lambert
Public Sector AI, Part 1: A Guide to Sovereign AI — The Revolution Will Be Sovereign

A 3-part series on AI procurement for government digital transformation. Part 1 of 3 — continue with Part 2: Agile vs. Goliath and Part 3: The Procurement Playbook.

Welcome to the new era of digital transformation in government. If you are a public sector leader, you are likely navigating the complex landscape of AI in the public sector. The pressure is immense: citizens demand better digital services, budgets are perpetually tight, and every technology vendor is promoting a new “generative AI” solution as the ultimate answer.

Two challenges define the moment. First: “Your AI is quietly old, not specialised and already out of date.” Second: it is no longer if you should pursue government AI adoption, but how — while bureaucracy is optimised to make you produce paperwork before you have done any of the meaningful tests you desperately need.

This guide argues that the AI revolution in government will not be a flashy, televised event. It will be a quiet, strategic shift towards a powerful new concept: sovereign AI.

The Sovereignty Imperative: Your Data, Your Rules in Public Sector AI

Data sovereignty in public sector AI

Across Europe, the groundbreaking EU AI Act has established a new global standard for AI governance. This is more than just regulation; it is a declaration of digital independence [1]. This legislation is accelerating a fundamental shift towards sovereign AI—the capability for a nation, region, or organisation to develop, deploy, and control its own AI systems. This ensures that critical government data, AI models, and the future of public services are not outsourced to the highest bidder in another hemisphere [2].

Why is this the cornerstone of any effective government AI strategy? When you are responsible for sensitive citizen data—from healthcare records to tax information—you cannot simply transfer it to a hyperscaler whose business model is opaque and whose priorities may not align with the public good. A recent McKinsey report highlights that 44% of technology leaders are delaying public cloud adoption due to data security concerns [3]. Another 31% state that data residency requirements prevent them from using public cloud services altogether. These leaders understand that true sovereignty is non-negotiable.

This is not about digital isolationism. It is about securing optionality and control. It is about ensuring the AI systems shaping your public services are aligned with your values, your laws, and your citizens’ best interests—not the quarterly earnings report of a foreign tech giant. The potential prize is enormous: McKinsey estimates that a successful sovereign AI strategy could unlock up to €480 billion in value annually by 2030 for Europe alone [3].

The Siren Song of Big Tech: Avoiding AI Vendor Lock-in

The AI vendor lock-in trap

The major technology players are, of course, eager to assist in your public sector digital transformation. They arrive with compelling presentations, promising to solve every challenge with their one-size-fits-all AI platforms. They offer the comfort of a familiar brand and the promise of an easy button for your AI journey. It is a tempting offer.

It is also a trap.

The publication that inspired this series, a joint paper by SAP and the Public Sector Network, explicitly warns about the critical risk of AI vendor lock-in [4]. This is the digital equivalent of quicksand. Once you are in, every attempt to escape only pulls you deeper. Your data is ingested into proprietary formats, your workflows become dependent on their specific tools, and your ability to innovate is shackled to their product roadmap and pricing structure.

“When choosing products and services, public sector organizations should also be aware of the risk of vendor lock-in, especially in a rapidly evolving market in which LLMs are being commoditized. We’re already seeing some finely-tuned models outperform more sophisticated, general-purpose models in particular domains and tasks.”

AI in the Public Sector, SAP / Public Sector Network [4]

This quote reveals a crucial trend: specialised, nimble models are already outperforming the giants. The market is shifting, and the large intermediaries are struggling to adapt. Once locked in, you are no longer a partner; you are a hostage. The very intermediaries promising to accelerate your AI transition become the biggest bottleneck, caught in their own sprawling processes and self-interest.

The Central Question for Your AI Procurement Strategy

This leads to an uncomfortable but essential question for every public procurement officer: if the big players are the undisputed leaders in AI, why are their own enterprise AI projects failing at a rate of 95%? (We dissect this statistic in Part 2.)

And if small businesses are achieving government AI adoption faster and more effectively, what does that signal about where true innovation lies?

The answer is clear: the future of AI in the public sector belongs to the small, the agile, and the sovereign — decentralisation will make you antifragile.

In the next post, we explore why the Davids are beating the Goliaths—and what that means for your public sector AI procurement strategy.

Continue reading: Part 2: Agile vs. Goliath in Government AI — A Procurement Guide

References

  1. European Commission. “European approach to artificial intelligence.” digital-strategy.ec.europa.eu
  2. Accenture. “Europe Seeking Greater AI Sovereignty, Accenture Report Finds.” November 3, 2025. newsroom.accenture.com
  3. McKinsey & Company. “Accelerating Europe’s AI adoption: The role of sovereign AI capabilities.” December 19, 2025. mckinsey.com
  4. Public Sector Network & SAP. “AI in the Public Sector.” 2025.

Insight42 provides expert guidance for public sector organisations navigating the AI transition — fast, secure and sovereign. See our Agentic AI Beratung (German) or Agentic AI Solutions.