Digital sovereignty is one of the key prerequisites for the responsible use of artificial intelligence (AI). Geopolitical tensions, stricter regulation and growing dependence on global technology providers are increasing the pressure on banks, insurers and asset managers. Anyone wishing to use AI should be able to demonstrate that data, models and systems are under their own control – both technically and organisationally.
Why does digital sovereignty affect the use of AI?
AI systems in the financial sector process sensitive data and support decision-making with tangible implications, for example in lending processes or risk management. In this context, digital sovereignty means more than just data protection. It is about transparent models, controlled data flows and the ability to operate systems securely even under changing political or legal conditions. Only those who retain this control can use AI in the long term and justify its use to regulators and customers.
Download the report now (in German only)
What does digital sovereignty entail in practice?
The white paper, which we produced in collaboration with T-Systems, describes digital sovereignty as the interplay of several levels. These include control over data and keys, the use of open and portable technologies, and traceable AI models. Equally important is operating within the European legal framework, including transparent access procedures and protocols. Only when these aspects come together can a robust foundation for trustworthy AI be established.
What, specifically, does the path to autonomous AI look like?
In this white paper, we outline a roadmap showing how your organisation can achieve greater digital sovereignty in three phases. The first step is to establish transparency and critically analyse data and AI applications to assess whether dependencies on providers and jurisdictions already exist. This assessment forms the basis for prioritising risks in a targeted manner and establishing initial governance structures.
In the second phase, the technical and organisational prerequisites are consolidated. These include establishing or utilising European AI and cloud platforms, clear regulations on key sovereignty, and verifiable processes for documentation and auditability. The aim is not merely to meet regulatory requirements in isolation, but to integrate them permanently into day-to-day operations.
In the third phase, digital sovereignty should finally be embedded in day-to-day business operations. Governance models, audit mechanisms and exit scenarios are regularly tested and refined. This creates a resilient structure that remains capable of functioning even under changing regulatory or geopolitical conditions.
What role do regulatory requirements play?
Regulatory frameworks such as the General Data Protection Regulation, the Digital Operational Resilience Act and the EU AI Act are tightening the requirements for transparency, traceability and resilience. For financial firms, this means they must be able to demonstrate where data is stored, who has access to it and how AI systems are managed. Digital sovereignty facilitates this demonstration because it combines clear lines of responsibility with verifiable processes – thereby reducing regulatory risks.
What specific benefits do financial firms derive from this?
Digital sovereignty builds trust – among regulatory authorities, customers and partners. At the same time, it creates scope for innovation: those who operate AI in a transparent, verifiable and controlled manner can test new use cases more quickly and scale them securely. As a result, digital sovereignty evolves from a mere risk mitigation tool into a strategic lever for the sustainable use of AI in the financial sector.
More KPMG Insights
Your contact
Peter Hertlein
Partner, Financial Services, IT Compliance & Cyber resilience
KPMG AG Wirtschaftsprüfungsgesellschaft