Pillar 03 · Residency

ALSO Group's Mark Appleton said something correct this week, and then spent the rest of the interview walking it back.

The correct part: "You cannot claim sovereignty if you don't understand how your data is being used to generate intelligence." Yes. Exactly. Hold onto that sentence.

The walk-back: the piece resolves, as these pieces always do, to hybrid and multi-cloud architectures that "combine hyperscale capabilities with sovereign controls," stitched together by a channel that "connects the dots between hyperscalers and partners." Sovereignty, it turns out, is an integration problem. Buy the right mix, wire it correctly, collect innovation and control.

This is residency wearing sovereignty's lanyard.

Residency is geography. It answers where the bytes sit. Sovereignty is jurisdiction. It answers who can compel their disclosure. These are different variables, and no quantity of "sovereign controls" bolted onto a hyperscaler changes the second one. A US-parented cloud's "sovereign region" in Frankfurt is residency. The parent remains subject to the CLOUD Act and FISA §702 regardless of which data centre holds the disk.

We don't have to argue this. We have testimony.

In June 2025, under oath before the French Senate, Microsoft France's legal director was asked whether he could guarantee that French citizens' data would never be handed to US authorities without French consent. His answer was one word. No. Not "unlikely." Not "we'd fight it." No. He explained, accurately, that a valid US order must be honoured, even for data sitting on European soil.

That is what a "sovereign control" is worth when the provider sits under foreign law. It is a control that depends entirely on the provider's willingness and legal ability to refuse. Microsoft told a parliament, under oath, that the ability is zero.

So "combine hyperscale capabilities with sovereign controls" is not a strategy. It's an oxymoron with a roadmap. You can combine hyperscale capability with the appearance of sovereign control. The appearance holds right up until someone files a warrant — or until your provider gets acquired.

Ask Amsterdam. The city deliberately chose Solvinity, a Dutch provider, specifically to stay out of US jurisdiction. In November 2025, US-based Kyndryl bought Solvinity. Amsterdam was notified one day before the announcement. Overnight, a sovereign choice became a subpoena target. No bytes moved. The jurisdiction moved to them.

Now, about the channel "connecting the dots." ALSO is a distributor — 135,000 resellers, 800 vendors. Of course its thesis is that sovereignty is solved by more integration. When your business is wiring hyperscalers to partners, every problem looks like it needs another connector. That's not dishonesty. It's the shape of the incentive. But connecting more vendors does not subtract a jurisdiction. It adds parties who can be compelled and surface that can be served. You cannot orchestrate your way out of the CLOUD Act. You can only add more companies obligated to comply with it.

Here is the distinction the ALSO piece needs and never makes. There are two kinds of control.

There is control that depends on a provider declining to comply. And there is control that survives the provider complying.

The first is policy. Contracts, transparency reports, "EU data boundaries," sovereign-region marketing — all of it lives or dies on a vendor's ability to say no to a court. Per sworn testimony, that ability does not exist for anyone under US law.

The second is architecture. If no single operator ever holds enough to reconstruct your data — keys held client-side, ciphertext erasure-coded across independent jurisdictions so that no one party ever possesses a usable copy — then a warrant served on any operator returns noise. Not because someone promised restraint. Because there is nothing there to hand over. Compelled disclosure becomes architecturally void rather than contractually discouraged.

Appleton's own test — you cannot claim sovereignty if you don't understand how your data is used to generate intelligence — fails the instant you accept a model where a foreign parent can be ordered to produce plaintext and legally cannot refuse. You don't understand how your data is used in that arrangement. You've been told, under oath, that you don't get to.

Sovereignty you can be talked out of is not sovereignty. It's an SLA with good public relations.

The window Appleton gestures at is real. He's right that boards are awake now, and right that AI raised the stakes. He's wrong about the fix. The fix is not a better-orchestrated dependency. It's removing the party who can be compelled from the position of holding anything worth compelling.

Design it so the warrant returns nothing. Everything else is a press release.

https://telecomreseller.com/2026/06/22/data-sovereignty-becomes-boardroom-priority-as-europe-pushes-new-digital-strategy-says-also-group/


Bias Declaration: I run SkyeConnex. We build CloudRAID — client-side-encrypted, erasure-coded sharding across independent jurisdictions, built specifically so that no operator, ours included, holds enough to comply with anyone's order. I have a direct commercial interest in you treating jurisdiction as an architecture problem. I'd have the identical interest if I sold sovereign regions for a hyperscaler. The difference is which of the two survives a subpoena.