
.webp)
Bill Gates recently called this “the most turbulent time in human history.” He is right. And in Europe, the silence from many leaders is deafening.
AI is no longer a productivity tool. It is cognitive infrastructure. It interprets information, makes recommendations, generates decisions and increasingly performs work that used to require human judgment.
The speed of this shift has surprised even the people who helped build modern AI. Geoffrey Hinton left Google in 2023 to warn about it. Mustafa Suleyman calls it a “proliferation problem.” Kai-Fu Lee framed it as a race between capability and governance. Right now, capability is winning.
In conversations with defence organisations, government agencies and enterprises across Europe, I keep returning to three points:
Together, they lead to one conclusion: sovereignty is the new moat - and it starts with visibility.
Bill Gates has raised an important question: which roles should remain human by deliberate choice? Caregiving. Teaching. Work that involves trust, empathy and accountability.
But he stops just short of the most important question:
How can an organisation protect human judgment if it does not know where machines have already taken over?
I sit down regularly with CIOs and compliance officers. I ask how many AI tools their employees are using. They give me a confident number. Then we show them what is actually running.
The real number is typically three to five times higher.
Consumer-grade tools. Personal accounts. Models that were never approved, never assessed, never seen by IT, legal or compliance. Sensitive data flowing into systems nobody authorised.
This is not a future risk. It is happening now - in organisations that believe they have AI under control.
You cannot reserve human judgment for the decisions that matter if you do not know where the machines have already taken over.
The first requirement for responsible AI is therefore not a new policy. It is visibility.
An organisation needs to know which AI systems and models are in use, who is using them, what data is being processed, where that data is going, what decisions the system can influence, what human oversight is in place, and what happens when the model changes.
Without that information, governance is largely an exercise in assumption.
Visibility is necessary, but it is not sufficient.
Most European organisations today run significant parts of their AI on American infrastructure, American models and American terms of service. Often, that is the fastest way to access advanced capability. It may also be commercially sensible for low-risk use cases.
But the strategic implications are frequently overlooked.
Every organisation that runs AI on a foreign provider’s infrastructure has made a governance decision - even if it did not feel like one.
It has decided that some of its data will be processed in systems it does not directly control, under terms it did not negotiate, and potentially in legal jurisdictions whose interests may not always align with its own.
The issue is not that American AI is bad. Some of the world’s strongest AI companies and models are American, and European organisations should use the best available technology where appropriate.
The issue is dependency.
What happens if a provider changes its pricing or terms? If a model update changes the behaviour of a critical system overnight? If a provider discontinues a product, or an acquisition changes its strategic priorities? If access is restricted for legal or geopolitical reasons? If a sensitive dataset cannot legally or safely be processed in a public cloud?
These are not only technical questions. They are questions of resilience, accountability and strategic autonomy.
Regulation can define obligations. It cannot create control where the underlying infrastructure is controlled by someone else.
That is why regulation without infrastructure is incomplete.
The most important risk may not be a dramatic science-fiction scenario. It may be the gradual concentration of intelligence, infrastructure and decision-making power in a small number of companies and governments.
Hinton warned about technology that could “greatly empower a handful of governments or companies.” That concentration is already developing.
A small number of technology providers increasingly control the most capable models, the computing infrastructure required to train and operate them, the data and platforms around those models, the interfaces through which organisations access them, and the pace and direction of capability development.
The rest of the world risks becoming a consumer of AI rather than a producer or governor of it.
Europe has seen this pattern before. Energy dependence was treated for years as an economic and commercial issue. It became clear, eventually, that it was also a question of resilience and sovereignty.
AI is likely to be even more consequential because it does not only power factories, transport or communications. It increasingly influences how organisations analyse information, make decisions and allocate resources.
Who controls the intelligence controls a growing part of the future.
European AI sovereignty should not mean rejecting global technology or trying to build every model independently.
It should mean retaining meaningful control over critical use cases.
That requires the ability to choose where AI runs, which models are used, where data is stored and processed, which laws and jurisdictions apply, how systems are monitored, how models can be changed or replaced, and how the organisation operates if an external provider becomes unavailable.
Sovereignty is therefore not isolation. It is the ability to make a deliberate choice rather than accepting dependency by default.
For some use cases, public cloud and external models may be entirely appropriate. For others - defence, healthcare, critical infrastructure, public administration and sensitive corporate operations - organisations may need AI that runs on infrastructure they control.
Several of our clients now run GRACE on their own infrastructure. This enables them to apply AI to classified or highly sensitive information that could never legally or safely be sent to a public cloud.
That is not a niche requirement. It is likely to become the baseline for organisations handling data that matters.
The debate about AI often becomes abstract. It focuses on jobs, superintelligence, regulation or national competition. Those questions matter, but organisations also need a practical path forward.
That path begins with three decisions.
1. Establish visibility
Create a complete and continuously updated inventory of AI systems, models, use cases, data flows and responsible owners. You cannot govern what you cannot see.
2. Make responsible AI easy to use
Employees often adopt unapproved tools because the official route is slow, restrictive or difficult to access. The answer is not simply to prohibit AI. Organisations need to provide approved tools that are fast, useful and available when employees need them. Effective governance makes the right path the easiest path.
3. Build control into the infrastructure
For sensitive or mission-critical use cases, organisations need the ability to run AI in environments they control. That means controlling access, data, models, logging, monitoring and human oversight. It also means having an exit strategy and the ability to change providers without rebuilding the entire operating model.
This is the purpose of GRACE AI Security. The AI Auto Registry identifies and records AI systems and use cases across an organisation. The Gatekeeper Agent helps detect shadow AI. Chat Guardian can identify sensitive information before it reaches a model. The AI Gateway controls which AI services employees can access.
The objective is not to stop organisations from using AI. It is to make responsible AI practical at scale.
Europe is approaching a decisive moment.
The choice is not between using AI and rejecting AI. It is between adopting AI by default and adopting it by design.
Organisations can continue to place sensitive data, critical workflows and strategic capability in systems they do not control. Or they can build the visibility, infrastructure and sovereignty required to use AI on their own terms.
Bill Gates is right that society needs a plan for the impact of AI on work and human value. Geoffrey Hinton is right that capability is moving faster than readiness. Mustafa Suleyman is right that proliferation and containment are central challenges. Kai-Fu Lee is right that AI will reshape the balance of power between nations and institutions.
But the practical conclusion is clear:
You cannot reserve human judgment if you cannot see where AI is already being used. You cannot govern AI if you do not control the infrastructure. And you cannot preserve sovereignty if critical intelligence is permanently dependent on someone else.
The wave is here.
Europe’s task is not to stop it. It is to ensure that it is built on infrastructure Europe can see, govern and control.
Stay up to date on our latest news and industry trends