Digital Sovereignty: European and Secure
Those who want to remain capable of acting digitally must not make themselves dependent – on individual providers, foreign legal jurisdictions, or systems that cannot be switched
Digital sovereignty means: you decide where your data is stored, who can access it, and which tools you work with – today and in five years' time. Since the CLOUD Act at the latest, it has been clear that an EU server location alone is not enough if a US provider stands behind it. And since licensing models and API prices can change overnight, companies know what vendor lock-in costs.
That is why we at Dreistein have for years relied on a European, open digital stack – for ourselves and for our customers. This page shows what that means in concrete terms.
The European Digital Stack – Our Building Blocks
For every building block of your digital infrastructure there is a European or open alternative that is technically on par with its US counterparts – without their legal risks:
- CMS: TYPO3. The open-source CMS with European roots – proven for over 25 years, with no licence fees and no vendor lock-in. Our core craft.
- AI: Mistral instead of US models. Powerful language models from France, fully within the European legal framework – or entirely self-hosted. How this works in practice is shown on our pages GDPR-compliant AI and dAi Pro.
- Cloud & collaboration: Nextcloud. Files, calendars and collaboration on your own infrastructure instead of Dropbox, Google Drive or OneDrive – more on this below.
- Hosting in the EU. With European providers, under European law – without any access possibility for US authorities via the CLOUD Act.
- Open standards & open source. Your data stays portable, your systems remain switchable. Sovereignty also means being able to leave at any time – including from us.
Why "EU servers" alone are not enough and how the CLOUD Act works is described in detail on our page GDPR-compliant AI.
Dreistein relies on Nextcloud
Nextcloud is an open-source cloud solution that offers companies, organisations and private individuals a secure, self-hosted alternative to US cloud services such as Dropbox, Google Drive or Microsoft OneDrive, AWS or Microsoft Azure. Nextcloud is a 100% European alternative to US cloud services. The software is developed by an independent community and offers:
✔ Complete data sovereignty – no sharing with third parties.
✔ GDPR-compliant solutions – without compromising on security.
✔ Open standards – no dependence on a single provider.
EU AI Act: What Businesses Need to Know Now
The EU's AI regulation applies in stages – and the next stage affects almost anyone operating a chatbot
The EU AI Act (Regulation 2024/1689) has been in force since August 2024 and becomes applicable in stages. The most important timeline for practice:
- Since February 2025: Prohibited AI practices (such as social scoring) are banned. At the same time, the obligation regarding AI literacy (Art. 4) applies: anyone deploying AI must ensure that their own staff can operate it competently.
- Since August 2025: Obligations for providers of large foundation models (GPAI).
- From 2 August 2026: The transparency obligations (Art. 50) become applicable: chatbots and AI assistants must be clearly identifiable as AI to users, and AI-generated content must be labelled.
- Later (end of 2027 / 2028): The obligations for high-risk systems – these deadlines were postponed by the "Digital Omnibus" of May 2026. For typical website assistants and knowledge chatbots, they are not relevant in any case.
What does this mean specifically for your chatbot or AI assistant? The good news: an assistant that answers questions about your products and services is not a high-risk system. However, tangible obligations remain – labelling as AI, transparency towards users, trained staff and clean documentation of what the AI does.
How we implement this: Our AI solutions based on dAi Pro come with the necessary building blocks – clear labelling of the assistant, answers with source references instead of a black box, a complete log of all AI calls for your documentation obligations, and help texts that explain to users what happens with their inputs. The data protection aspect is covered on our page GDPR-compliant AI.
Note: This overview does not replace legal advice – it shows which technical and organisational course you should set now.