← /episodes
[ S01E07 ]EN2026-06-1219:07

S01E07 - Sovereign storage is not enough: why European data lakes are missing the evidence layer

S01E07 - Sovereign storage is not enough: why European data lakes are missing the evidence layer
▶ play episode
Download ↓

US cloud providers control more than 70% of European cloud infrastructure. Microsoft confirmed under oath at a French Senate hearing in 2025 that it cannot guarantee data sovereignty for European customers facing a legally justified US order. The market's response: European sovereign data lakes that centralise business data from accounting, CRM, HR, and ERP into a private database environment with no CLOUD Act exposure. Sovereign cloud spending in Europe grows 83% year-over-year in 2026.

Michael and Nadine explain what a European sovereign data lake does — and what it does not. They walk through how these platforms deliver EU-only data residency, no US sub-processors, open standards without vendor lock-in, and direct AI connectivity. But they also ask the question most providers do not answer: what happens when a regulator does not ask where your data is, but what was done with it — when, by whom, and on which legal basis?

An audit log inside a database is not proof — it is a file that can be altered. Built-in logging without cryptographic anchoring is not tamper-evident. And the evolution of compliance over time is something no data lake records. That is the missing layer that leaves organisations exposed during investigations under EU AI Act Article 12, NIS2, DORA, and GDPR Chapter V — even when they run fully European infrastructure. Attesto delivers that layer: cryptographically irrefutable proof via the Proof of Evolution system, on top of any sovereign data lake. The Nova/IVC layer is already running live in production.