The institutions that protect rights and hold power to account run on software that was never built for them.
Courts, investigators, newsrooms, parliaments, and civil society organisations depend on tools designed for corporate customers, hosted by a handful of providers, and governed by the laws of countries that are not their own. When those providers change their terms, their prices, or their political priorities, the institutions relying on them have no say.
Work that serves the public should not depend on someone else's jurisdiction.
This is not a theoretical concern. Foreign laws can compel providers headquartered outside the EU to disclose the data they hold, regardless of where the servers sit. Sanctions, export controls, and shifting foreign policy can cut off access overnight. For any organisation handling sensitive testimony, investigative material, or politically contested data, that is an unacceptable structural risk.
The response cannot be better contracts with the same providers. It has to be structural. The software itself must be sovereign — built, hosted, and governed within the jurisdiction of the people who rely on it.