Weekly Backlog Week 31/2026
🧠 Editorial This edition primarily focuses on digital sovereignty—from both a technical and …

This edition primarily focuses on digital sovereignty—from both a technical and political perspective.
I particularly recommend the guest article by Nish Sribavan, who explains why the real issue with the German government’s Microsoft expenses isn’t the cost, but the lack of exit capability. Also worth checking out is the LinkedIn Post of the Week by Klaus Wiedenmann, who shares his experiences with kDrive by Infomaniak as an alternative to OneDrive.
Additionally, we cover the extension of chat control, the debated AI kill switch in the USA, the again shaky EU-US data agreement, and more news from Cloud, Security, AI, and Open Source.
Enjoy reading!
The EU has extended the transitional regulation for chat control until April 2028. Providers of “certain” (🤡) communication services are thus still allowed to automatically analyze private communications for depictions of sexual violence against children and grooming indications. This is justified by the protection of children.
Child protection is important. There’s no debate about that for me.
That’s why this approach doesn’t convince me at all.
If the declared goal is really the perpetrators, why does the measure focus on communication channels that criminals are likely to avoid anyway? Those who abuse children know they are committing serious crimes. I find it hard to believe that such perpetrators would communicate via channels that can be automatically monitored.
In the end, it mainly captures the communication of millions!!! of people who have never been suspected of a crime. And that’s what worries me.
With each new regulation, the technical infrastructure for monitoring private communication grows. Private providers take on state control tasks. Today, this may be justified solely by child protection. However, I have little faith that a surveillance infrastructure, once created, will remain permanently limited to this purpose.
Experience shows the opposite. Technical possibilities arouse political desires. What begins with child protection today can be expanded tomorrow to terrorism, hate speech, disinformation, allegedly wrong political attitudes, or other criminal offenses. The history of state surveillance provides countless examples of this.
That’s why I view this development critically. Not because I question child protection, but because I doubt that this measure effectively targets the actual perpetrators. Instead, we are gradually getting used to the automated control of private communication.
Child protection needs effective law enforcement. What we don’t need is the creeping normalization of surveillance under an argument that no one seriously wants to oppose.
In the USA, political pressure is growing on developers of powerful AI models. With the bipartisan “AI Kill Switch Act,” manufacturers are to be required to provide technical mechanisms to restrict or shut down AI models in an emergency. The initiative is justified by concerns about uncontrollable risks of powerful AI.
At first glance, this seems like a debate about safety, but on closer reading of the bill, it’s about much more.
A mandatory kill switch would not only change the development and operation of modern AI systems. It would give the US government a tool that goes far beyond classic regulation. Whoever can decide on the shutdown or restriction of an AI model gains significant influence over its use.
And this influence does not end at the borders of the USA.
Today’s leading AI models mostly come from American companies. They are used worldwide—by companies, research institutions, public administrations, and entire start-ups build their business models on them. Decisions made in Washington can therefore have immediate effects on users far outside the United States.
This is exactly what heise points out: As long as such a law does not overly burden its own economy, it could be used in the future to exert political pressure on other states or even on individual US AI companies.
The “AI Kill Switch Act” is still just a bill. Nevertheless, the debate already shows how closely technological leadership and political power are now intertwined.
With the Data Privacy Framework (DPF), the EU wanted to finally create legal certainty for the transfer of personal data to the USA three years ago. It was already the third attempt after Safe Harbor and Privacy Shield, both of which failed before the European Court of Justice.
Now this agreement is under pressure again.
The reason is not a new data protection debate, but a decision by the US Supreme Court. It confirmed that the President can dismiss the head of the Federal Trade Commission (FTC). This agency plays a key role in the DPF.
The current heise commentary points this out.
The agreement assumes in many places that the FTC acts independently of the government. If this assumption falls away, the legal basis of the DPF also wobbles.
That’s why the data protection association NOYB around Max Schrems is already preparing the next lawsuit.
However, another aspect of the commentary is noteworthy.
While the legal basis is becoming increasingly fragile, the economic dependency remains. Many companies continue to rely on US hyperscalers because they consider them indispensable. The legal uncertainties of recent years have hardly changed that.
However, the environment has changed.
At the latest, the cases in which US companies have blocked accounts or restricted digital services under political pressure show that the discussion has long since gone beyond data protection. Whoever controls central digital infrastructures also has political room for maneuver.
The heise commentary draws a clear conclusion from this: Even a new agreement would not solve the fundamental problem. As long as European data is processed on infrastructures subject to the influence of a foreign government, every agreement remains vulnerable.
The debate is therefore no longer just about data protection.
It’s about digital sovereignty.

Guest article by Nish Sribavan
481 million euros. That’s how much the German government spent on Microsoft licenses in 2025, 38 percent more than the previous year. The figures come from responses by the Federal Ministry of Finance to parliamentary inquiries and they draw a clear curve from around 274 million euros in 2023 to nearly 348 million in 2024 to now over 481 million. Since 2017, the payments have totaled more than 1.9 billion euros. This does not include the expenses of states and municipalities.
The outrage followed promptly. The trade press speaks of the “dependency trap,” and in the comment sections, calculations are made about what could have been built with half a billion euros. I took a closer look at the debate and my finding is uncomfortable. The sum is not the scandal. The scandal is what the government doesn’t get for this money.
Two Camps, One Common Mistake
The debate follows familiar paths. One camp points to the bill and demands a quick exit from the Microsoft world. The other camp refers to openDesk, the state-funded open-source workplace, as a ready alternative.
A look at the same ministry responses, however, is sobering. openDesk currently has 8,756 licenses in the government. About 90 percent of them run at a single agency, the Robert Koch Institute. It’s a pilot project and valuable as such. It’s not yet a counter-model to hundreds of thousands of Microsoft workplaces. Those who present it as proof of existing sovereignty confuse intention with the state.
Both camps are thus arguing over the same question. What does it cost? One calculates the licenses, the other the conversion. This argument falls short. Because the crucial question with strategic technology dependencies is not what staying or switching costs. It is whether an organization could still switch at all if it had to.
What the Government Didn’t Buy
For 1.9 billion euros, the government got functioning workplaces. That’s no small thing and I consider this expenditure justifiable. What is not justifiable is that the contracts and processes behind it lack a tested exit path.
Exit capability sounds like a topic for contract lawyers, but it’s an operational discipline. In my work on “Sovereign Cloud,” I’ve spoken with executives of major providers as well as those responsible on the user side. A pattern runs through almost all conversations. Exit strategies exist, but only on paper. There’s the clause in the contract and the chapter in the governance manual. What almost never exists are three things: truly tested data portability, interfaces usable outside the provider ecosystem, and an operational model for the first day after the switch. An exit strategy that has never been rehearsed is not a strategy. It’s a guess.
Why this is more than a theoretical concern was shown in 2025. After US sanctions, the chief prosecutor of the International Criminal Court lost access to his email account. The exact processes were disputed afterward. What matters is something else. An institution had to experience in ongoing operations that its ability to work depended on decisions outside its control. Digital dependency doesn’t announce itself with tanks. It grows quietly, contract by contract, integration by integration, until the moment comes when a switch is no longer possible in 30 days, but in three years, if at all.
The Legal Framework Helps, But It Doesn’t Solve the Problem
One might argue that regulation is addressing this. Indeed, the EU Data Act prohibits switching and data withdrawal fees entirely from January 2027, significantly lowering the legal and financial hurdles of switching providers. That’s real progress and shouldn’t be downplayed.
But the Data Act eliminates fees and contract clauses, not the technical barriers, such as proprietary formats, deep integration into managed services, and lack of operational know-how for alternatives. Exit capability cannot be decreed. It is architectural work and practice.
🧠 Editorial This edition primarily focuses on digital sovereignty—from both a technical and …
📰Tech-News: The First Documented AI Agent Hack is Here Hugging Face operates the world’s …
🧠 Editorial This week had it all: open databases, open GitHub repositories, open questions about …