WINNIIO Perspectives — Whitepaper V — Apr 2026
Digital Sovereignty or Digital Dependency?
Why Swedish Manufacturers Need to Reclaim Control of Their AI Infrastructure
Apr 2026
“Your most sensitive production data — process parameters, machine configurations, quality signatures — is almost certainly being processed on servers you do not own, in jurisdictions whose laws do not protect you. This is not a hypothetical risk. It is the default state of industrial AI deployment in 2026.”
The Infrastructure Nobody Talks About
Swedish manufacturing has embraced digital transformation at pace. IoT sensors monitor machine health in real time. AI models predict maintenance windows. Digital twins model production flows. The efficiency gains are real and measurable.
What is rarely discussed is the infrastructure layer on which all of this intelligence runs.
For the overwhelming majority of Swedish industrial companies, AI workloads are processed on infrastructure owned by three global technology corporations: Amazon Web Services, Microsoft Azure, and Google Cloud. These providers operate data centers across multiple jurisdictions, subject to the legal frameworks of the countries in which they operate — frameworks that include extraterritorial reach into data held by their corporate entities, regardless of where that data physically resides.
This is not a theoretical concern raised by data privacy advocates. It is a documented legal reality. US cloud providers operating under the CLOUD Act of 2018 can be compelled to produce data held on non-US infrastructure in response to US government orders — without necessarily notifying the data owner or the relevant national authority. For a Swedish steel manufacturer whose competitive advantage resides in proprietary process parameters and quality recipes, this is a commercial risk of the first order.
“NIS2 does not ask who hosts your data. It asks whether you control your infrastructure. For most manufacturers running cloud-dependent AI, the honest answer is no.”
Four Structural Dependencies That Compound Over Time
- Latency. A cloud round-trip takes 50 to 200 milliseconds. For real-time process control — managing the temperature ramp in a heat treatment furnace, responding to a grid frequency event — this is unacceptable. Industrial processes operate on millisecond timescales. The physics does not wait for a server response from a data center in Ireland.
- Vendor lock-in. Proprietary APIs, proprietary data formats, and proprietary model registries create switching costs that grow every year. When a cloud provider changes pricing, discontinues a service, or becomes subject to geopolitical disruption, the manufacturer has no alternative.
- Data volume economics. A modern metal processing facility generates terabytes of sensor data per day. Uploading this volume to a cloud for processing has a cost that scales linearly with production. Edge processing eliminates this cost category entirely for workloads that do not require centralized aggregation.
- Regulatory exposure. As the EU regulatory framework tightens, manufacturers whose AI runs on third-party cloud platforms face a growing compliance gap. Demonstrating that AI decisions are traceable, that data never left the jurisdiction, and that human override is always possible is straightforward on infrastructure you control. It is significantly more complex on infrastructure you rent.
The Sovereign Architecture
The architecture that eliminates these vulnerabilities exists, and it is built entirely on open standards.
The core principle is simple: intelligence should be created where data is generated. Sensor data is processed at the facility — on industrial hardware running AI models optimized for edge deployment. The decisions that require speed happen locally. The insights that benefit from aggregation across multiple sites are shared via federated protocols that never expose raw data.
The Standards Stack
- LF Edge — the Linux Foundation's vendor-neutral edge platform (Apache 2.0) — validated by industrial actors including Eaton for energy management workloads.
- Asset Administration Shell (IEC 63278-1), maintained by IDTA, provides the standardized data model for digital twins under Industry 4.0. Security specification published June 2025.
- OPC UA (IEC 62541) — universal communication standard for IIoT, supported by every major PLC and SCADA vendor.
- Kubernetes container orchestration enables cloud-agnostic deployment. The same containerized workload can run on on-premise industrial hardware, a private cloud, or any public cloud provider, with no code changes.
Research from Chalmers University of Technology has documented AI model optimizations that achieve up to 83 percent reduction in inference energy consumption and 18-times faster inference on edge hardware, without compromising model accuracy and without data leaving the facility.
“The goal is not independence from technology providers. It is independence from any single technology provider — the architectural property that makes every component of the stack a commodity rather than a dependency.”
The Regulatory Dimension
For Swedish manufacturers operating under NIS2 as “essential entities,” the compliance obligations are specific and auditable. The NIS2 transposition in Swedish law carries penalties of up to EUR 10 million or 2 percent of global annual turnover for non-compliant entities.
A sovereign edge architecture directly satisfies the infrastructure control requirements that NIS2 imposes. When AI inference runs locally, when production data never leaves the OT network in unencrypted form, when every edge node is identifiable and authenticated through mutual TLS certificates, and when the entire system has a documented fallback hierarchy — the compliance case is structurally built into the architecture rather than retrofitted through certification processes.
The EU AI Act's requirements for traceability and human oversight are similarly addressed by design. When AI decisions are logged locally, when every decision passes through a documented validation pipeline, and when operators retain visible, exercisable override capability, the transparency requirements of the Act are met at the architectural level.
The Economics of Sovereignty
The conventional framing positions sovereign infrastructure as a premium. The arithmetic of the alternative does not support this framing.
Cloud compute costs for continuous industrial AI workloads scale with data volume and inference frequency. A facility generating terabytes of sensor data per day, running multiple AI models in continuous operation, faces a cloud bill that grows every year as AI applications proliferate. The sovereign edge architecture converts this variable cost into fixed infrastructure — industrial hardware with a known depreciation profile, maintained by the same operational team that manages the production equipment.
For a manufacturer operating at scale across multiple facilities, the crossover point — at which sovereign edge infrastructure costs less than cloud-dependent alternatives on a total cost of ownership basis — is typically reached within two to three years of deployment. Beyond that point, the gap widens in favor of the edge architecture every year.
Moving from Dependency to Sovereignty
- Audit where your AI runs. Most manufacturers who undertake this exercise are surprised by what they find — not because the providers have misled them, but because the question has simply not been asked systematically.
- Build in parallel. A containerized edge deployment can run alongside existing SCADA and cloud integrations, progressively taking on more workloads as it is validated in each context.
- Design for replication from day one. The value of a sovereign edge architecture multiplies with the number of facilities it covers. The right design enables deployment in a new facility within two weeks, with documented configuration rather than custom engineering.
The question of digital sovereignty is ultimately a question about where industrial intelligence will be created and who will control it. The manufacturers who establish sovereign infrastructure now will not only be better positioned for compliance; they will own a strategic capability that their cloud-dependent competitors will spend years trying to replicate.
WINNIIO AB develops edge-native AI platforms and digital twin implementations for European industrial manufacturing. This paper reflects independent research and analysis.
References: EU Data Act (2025); NIS2 Directive (EU 2022/2555); EU AI Act (2024/1689); CLOUD Act (US, 2018); EU Taxonomy Regulation (2020/852); IEC 62541 (OPC UA); IEC 63278-1 (Asset Administration Shell); IEEE 2874-2025 (Spatial Web); LF Edge / EdgeX Foundry documentation; Embedl technical documentation (Chalmers University of Technology, 2025); Gaia-X Industrial Data Space specifications.