In 1883, Auguste Kerckhoffs published a rule in the Journal des sciences militaires that still holds every secure system together: a cipher must not depend on its method being secret. You should be able to hand that method to your enemy without harm.
Publish the method. Protect the key.
A hundred and forty-three years later, we do the opposite with AI.
We keep the method secret, because a vendor called it a moat. And we hand over the key without thinking: every client file, every contract, every piece of proprietary code pasted into someone else's model.
Last June, before a French Senate committee of inquiry, Microsoft France was asked whether it could guarantee that French data would never reach US authorities without French authorisation. Under oath, the answer was: "No, I cannot guarantee it." It has never happened, he added. So far.
This is not a scandal, and it is not an accusation. It is a jurisdiction, and it has a name: the CLOUD Act. A 2018 law that compels a US-headquartered provider to hand over data it controls, wherever that data sits. A Paris or Frankfurt region changes nothing: the obligation follows the company, not the server.
It is not about where your data lives. It is about who can be compelled to hand it over.
And legal dependency is not the only kind. A model you rent can be deprecated, repriced, retuned — no notice, no court required. Its judgement calls are its vendor's, not yours. That is not a grievance: a vendor optimises for its shareholders, that is the job. But you cannot audit an incentive you cannot see.
Last time I called the answer Intentional Coding: taking command of how software gets built. Sovereignty is the same idea one floor up: command over where your knowledge lives.
Field report, then, not manifesto.
I run my own stack: open-weight models on my own hardware, no cloud model in the loop. What surprised me is how ordinary that has become.
And the part most sovereignty pieces leave out, so I say it first: self-hosting is not cheaper. You need the engineers, the updates, the vulnerabilities that are now yours to patch. Below real volume an API wins on cost, and pretending otherwise is how you lose an argument you should win.
What remains is narrower, and stronger: on a well-defined domain task, a model tuned on your data can match a far larger one. Not on everything. On your thing.
Which is the point. Your excellence lives in your data, your corpus, your way of working: that is the key. The architecture, the controls, the proof that it works: that is the cipher. Publishing it costs nothing and buys trust.
Share the method. Protect the know-how.
Where do you draw that line — and do you know where your data sleeps tonight?
AISovereignty #CloudAct #NIS2 #Cybersecurity #IntentionalCoding
Sources:
• Auguste Kerckhoffs, "La cryptographie militaire", Journal des sciences militaires, 1883 — full text free on Gallica (BnF).
• Microsoft France before the French Senate committee of inquiry into public procurement and digital sovereignty, 18 June 2025. Public transcript: senat.fr (hearing held in French; the quote is translated).
• CLOUD Act (Clarifying Lawful Overseas Use of Data Act), United States, 2018.
• ANSSI, SecNumCloud framework: cyber.gouv.fr

Top comments (0)