The Point
European companies cannot replace US technology platforms; instead of complete independence, they need a resilient hybrid infrastructure with targeted risk management.
Summary
- Boehringer Ingelheim and similar corporations depend on US platforms for core functions, for which there are no European alternatives with sufficient performance capacity.
- The strategy is: Store sensitive and critical data in European data centers, use platforms internationally where dependency is acceptable.
- The company registers over 20,000 cyberattacks monthly; protective measures include AI-powered monitoring, multi-factor authentication, and rapid isolation protocols.
People
- Andreas Henrich (Corporate Vice President IT Infrastructure, Boehringer Ingelheim)
Topics
- Digital sovereignty
- Cloud infrastructure
- Cybersecurity
- Risk management
Clarus Lead
The commentary refutes the narrative widespread in Europe of an immediate exit from US technologies. A single US government export ban (example: AI model Mythos 5 by Anthropic) demonstrates political vulnerability, but Boehringer Ingelheim argues: European alternatives do not exist and would cost innovative capacity. The decision-making scope lies in selective dependency and technical safeguarding, not in completeness.
Detailed Summary
The pharmaceutical company concretizes its model at three points. First: Hybrid Infrastructure. Sensitive data is mirrored in German co-locations and proprietary data centers; simultaneously, internationally networked teams use cloud-based platforms for marketing, CRM, and research. This decoupling enables availability even if individual providers fail or new US export restrictions emerge.
Second: Cybernetic Threat Landscape. The company records over 20,000 attack attempts monthly. With AI, attacks become more sophisticated; phishing remains the primary entry point. Organized crime targets critical infrastructure and production availability. Boehringer Ingelheim responds with dual security teams (defense and penetration testing), AI-powered log analysis, and rapid isolation mechanisms.
Third: Innovation as Counterweight. The text emphasizes that AI-based drug discovery significantly shortens development cycles and enables virtual side effect simulations. Complete technical autarky would negate these advantages.
The conclusion: Digital sovereignty means operational capability even under disruption, not independence.
Key Statements
- Complete European independence is unrealistic and is contradicted by lack of scaling capacity.
- Critical and sensitive data must be available in controlled, European environments; non-critical data can run in US clouds.
- Cybersecurity requires multi-layered monitoring (AI log analysis, multi-factor authentication) and rapid isolation capability, not just platform switching.
Critical Questions
Evidence and Data Basis: The text mentions "over 20,000 attack attempts monthly." Are these industry average values, or do they apply specifically to Boehringer Ingelheim? Without comparative values, the relevance of this figure remains unclear.
Conflict of Interest: Andreas Henrich is an employee of Boehringer Ingelheim and argues for a strategy the company has already implemented. To what extent could the argument be colored by economic dependency on US platforms? Would an independent infrastructure auditor have reached the same conclusion?
Alternatives and Causality: The text claims European alternatives do not exist. This is partially true (hyperscaler scaling), but: Which European data space initiatives (e.g., Gaia-X) could reduce dependencies in the medium term? The text does not refute that investments in European infrastructure are worthwhile at all.
Risk Prioritization and Implementation: The strategy is formulated, yet concrete metrics are missing. How is it measured whether a "hybrid architecture" is sufficient? By which criteria is it decided which data runs in Europe and which in US clouds? Are these trade secrets or lack of operationalization?
Geopolitical Dynamics: The text example (Anthropic ban) dates from 2026. The list of possible future US export restrictions could grow longer. Does the hybrid strategy also cover scenarios where not just individual AI models, but entire hyperscaler services are restricted?
Industry Generalizability: Boehringer Ingelheim is a large, capital-intensive pharmaceutical company with its own IT budget for data centers and security teams. Is this strategy also practicable for mid-market companies that lack the resources for dual infrastructure?
Sources
Primary Source: "Digital Sovereignty Requires Pragmatic Risk Management" – ComputerWeekly, Andreas Henrich (Boehringer Ingelheim), 23 July 2026 – https://www.computerweekly.com/de/meinung/Digitale-Souveraenitaet-braucht-pragmatisches-Risikomanagement
Access: 23.07.2026 | Access Scope: complete | Source Type: Guest article/Opinion piece
Verification status: ✓ 26.07.2026
This text was created with the assistance of an AI model. Editorial Responsibility: clarus.news | Fact-Check: 26.07.2026