<?xml version="1.0" encoding="UTF-8"?>
<rss 
    version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/" 
    xmlns:content="http://purl.org/rss/1.0/modules/content/" 
    xmlns:atom="http://www.w3.org/2005/Atom" 
    xmlns:media="http://search.yahoo.com/mrss/" 
>
    <channel>
        <title><![CDATA[DocuPoint]]></title>
        <description><![CDATA[A lifetime inside the Microsoft ecosystem. Still standing. Still honest about what works and what doesn&#x27;t. ]]></description>
        <link>https://www.docupoint.eu</link>
        <image>
            <url>https://www.docupoint.eu/favicon.png</url>
            <title>DocuPoint</title>
            <link>https://www.docupoint.eu</link>
        </image>
        <generator>Ghost 6.52</generator>
        <lastBuildDate>Wed, 15 Jul 2026 13:11:08 +0200</lastBuildDate>
        <atom:link href="https://www.docupoint.eu" rel="self" type="application/rss+xml"/>
        <ttl>60</ttl>

                <item>
                    <title><![CDATA[AI Readiness Is Balanced, Not Bought: The Two Axes of AI That No Licence Can Buy]]></title>
                    <description><![CDATA[Two companies buy the same AI tool in the same quarter. Same vendor, same per-seat price, same glossy rollout email to staff. A year later one of them has quietly rebuilt a core process around it and can point to the hours it saves. The other is trying to remember the login.]]></description>
                    <link>https://www.docupoint.eu/blog/ai-readiness-is-balanced-not-bought-the-two-axes-of-ai-that-no-licence-can-buy/</link>
                    <guid isPermaLink="false">6a4a1dacc6f8b400014914a6</guid>

                        <category><![CDATA[AI Strategy]]></category>
                        <category><![CDATA[AI-readyness]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sun, 12 Jul 2026 06:00:35 +0200</pubDate>

                        <media:content url="https://images.unsplash.com/photo-1465447142348-e9952c393450?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDF8fGludGVyc2VjdGlvbnxlbnwwfHx8fDE3ODMyNDIzODl8MA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1465447142348-e9952c393450?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDF8fGludGVyc2VjdGlvbnxlbnwwfHx8fDE3ODMyNDIzODl8MA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" alt="AI Readiness Is Balanced, Not Bought: The Two Axes of AI That No Licence Can Buy"/> <p>Two companies buy the same AI tool in the same quarter. Same vendor, same per-seat price, same glossy rollout email to staff. A year later one of them has quietly rebuilt a core process around it and can point to the hours it saves. The other is trying to remember the login.</p><p>The gap between them is not the software. They bought identical software. When MIT's NANDA initiative examined why most enterprise generative-AI pilots returned nothing, the cause was not the model. <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/?ref=docupoint.eu" rel="noopener nofollow">The pilots failed on how companies approached them, not on the quality of the tool</a>. Gartner watched the same split from the outside and predicted that <a href="https://www.gartner.com/en/newsroom/press-releases/2024-07-29-gartner-predicts-30-percent-of-generative-ai-projects-will-be-abandoned-after-proof-of-concept-by-end-of-2025?ref=docupoint.eu" rel="noopener nofollow">at least 30% of generative-AI projects would be abandoned after the proof-of-concept stage by the end of 2025</a>. Same tools. Opposite outcomes.</p><p>So if the tool is identical, the difference lives somewhere else. It lives in whether the company around the tool was ready to use it.</p><p><strong>Readiness has two axes, and a pile of licences moves only one of them.</strong> <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">McKinsey counts only about 6% of firms as genuine AI high performers</a>, and finds that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">only around 39% of organizations report any bottom-line impact from AI at all, most of it under 5%</a>. <a href="https://www.bcg.com/publications/2024/wheres-value-in-ai?ref=docupoint.eu" rel="noopener nofollow">BCG puts just 26% of companies past pilots into real value, which leaves 74% with nothing to show</a>. The winners are not spending more on models. BCG's rule of thumb, drawn from studying them, is blunt: <a href="https://www.bcg.com/press/30september2025-ai-leaders-outpace-laggards-revenue-growth-cost-savings?ref=docupoint.eu" rel="noopener nofollow">70% of what makes AI work is people and process, 20% is technology and data, and only 10% is the algorithms</a>.</p><p>This article takes readiness apart along its two axes, technology and organization. It borrows a ten-domain map so you can see where a business actually stands, explains why a Copilot licence is the last 10% rather than the first step, and ends with a self-scan you can run before lunch.</p><p>The uncomfortable headline is this: the part of readiness you can purchase is the part that matters least.</p><h2 id="two-axes-not-one-dial">Two axes, not one dial</h2><p>Most companies treat AI readiness as a single dial. Turn it up by spending more. Buy better tools, buy more seats, buy a bigger model, and readiness goes up. That mental model is why so much money produces so little.</p><p>Readiness is not one dial. It is two axes that have to move together.</p><p>The first axis is technology. Your data has to be reachable and reasonably clean. Your systems have to connect. There has to be somewhere sensible and secure for AI work to happen. This is the axis vendors talk about, because it is the axis they sell.</p><p>The second axis is organization. Someone has to pick a real process and redesign it around the new capability. People have to be trained to work differently. Results have to be measured, and the ones that fail have to be dropped. This is the axis nobody invoices you for, and it is the one that decides whether the first axis ever pays off.</p><p>Microsoft's own readiness research, drawn from its survey of a thousand organizations, shows how rarely the two move in step. Roughly <a href="https://www.microsoft.com/en-us/microsoft-cloud/blog/2026/05/14/from-ai-ambition-to-frontier-transformation-readiness-defines-the-leaders/?ref=docupoint.eu" rel="noopener nofollow">30% of organizations reach strong technology readiness, and a similar share reach organizational readiness, but only the firms that achieve both consistently deliver impact</a>. That is a vendor's own data, so read it with a raised eyebrow, but it matches what the independent researchers keep finding. McKinsey reports that the high performers were far more likely to have <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">fundamentally redesigned their workflows rather than sprinkled AI on top of the old ones</a>. Redesigning a workflow is an organizational act, not a technical one.</p><p>Put the two axes on a grid and four kinds of company appear. Strong technology and a stalled organization gets you an expensive pilot that nobody adopts, the classic shelf of unused licences. A motivated organization sitting on chaotic data gets you enthusiasm that hits a wall the first time the tool returns confident nonsense. Weak on both is most of the market. Strong on both is the thin minority that shows up in every "AI leaders" statistic. The tools are the same across all four boxes. The position on the grid is what differs.</p><h2 id="a-map-of-ten-domains-borrowed-and-de-branded">A map of ten domains, borrowed and de-branded</h2><p>"Technology" and "organization" are the right two axes, but they are too coarse to act on. You cannot fix "organization." You can fix the specific things that make it up.</p><p>One of the more useful breakdowns comes from Microsoft's AI Readiness framework, which splits readiness into <a href="https://www.microsoft.com/en-us/microsoft-cloud/blog/2026/05/14/from-ai-ambition-to-frontier-transformation-readiness-defines-the-leaders/?ref=docupoint.eu" rel="noopener nofollow">ten domains grouped under technology and organization</a>. It is a vendor framework, and vendor frameworks tend to route you toward the vendor's products, so take the map and leave the sales pitch. Stripped of branding, the ten domains describe any business honestly, whether you run on Microsoft, on open-source models hosted in Europe, or on a mix.</p><p><strong>On the technology axis, six domains:</strong></p><ul><li><strong>GenAI models.</strong> The models themselves, and whether the ones you use fit the job.</li><li><strong>GenAI applications.</strong> The actual apps and interfaces where people meet the AI.</li><li><strong>Cloud and hosting.</strong> Where the work runs, and whether that place is appropriate for your data and your rules.</li><li><strong>Data.</strong> Whether your information is organized, reachable, and clean enough to trust.</li><li><strong>Information security.</strong> Whether AI access widens your attack surface or is contained.</li><li><strong>Integration.</strong> Whether the tool can reach your other systems, or sits in a silo.</li></ul><p>On the organization axis, four domains:</p><ul><li><strong>Business strategy.</strong> Whether AI is aimed at a real business outcome or just adopted because everyone else is.</li><li><strong>Organization and culture.</strong> Whether people are willing and able to change how they work.</li><li><strong>AI strategy and experience.</strong> The skills, the literacy, the accumulated hands-on know-how.</li><li><strong>AI governance.</strong> Whether you can explain what the AI did, catch problems early, and stay inside the law.</li></ul><p>Notice the balance. Six technical domains, four organizational, and yet BCG's evidence says the four organizational ones carry <a href="https://www.bcg.com/press/30september2025-ai-leaders-outpace-laggards-revenue-growth-cost-savings?ref=docupoint.eu" rel="noopener nofollow">70% of the weight</a>. Fewer domains, more weight. That is the whole trap in one sentence: the axis with the most impact has the fewest boxes to tick and the least outside help for sale.</p><p>You do not need to score a perfect ten. You need to know which domains are weak, because a chain of ten breaks at the weakest link. A brilliant model pointed at disorganized data produces faster nonsense. A perfectly governed system nobody wants to use produces nothing. The map is not a shopping list. It is a diagnostic.</p><h2 id="why-a-stack-of-licences-is-not-readiness">Why a stack of licences is not readiness</h2><p>Here is the trap almost every company walks into, and it is an honest mistake. AI arrives as a product. A licence. A per-seat price. A logo in the corner of software you already own. So it gets bought like any other software: approve the budget, buy the seats, send the announcement, and wait for the productivity to appear.</p><p>It does not appear, because a licence only touches the technology axis, and only part of it. Buying seats does not organize your data, redesign a workflow, retrain a team, or set up a way to measure whether any of it worked. Those live on the axis no purchase order reaches.</p><p>The evidence on this is unusually consistent. The MIT researchers were clear that the failed pilots <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/?ref=docupoint.eu" rel="noopener nofollow">failed on approach, not on model quality</a>. Gartner found that the organizations most satisfied with their AI results were the ones that <a href="https://www.gartner.com/en/articles/genai-project-failure?ref=docupoint.eu" rel="noopener nofollow">spent roughly 30% more on data, governance, and talent</a>, not on models. And the foundation underneath it all is data: Gartner reports that <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk?ref=docupoint.eu" rel="noopener nofollow">63% of organizations either lack the data-management practices that AI needs or are not sure whether they have them</a>. None of those gaps has a licence key.</p><p>The engineers who build these systems say the same thing in plainer language. A widely shared field guide on enterprise AI, "Foundations First," argues that the work that decides whether AI pays off happens before the model: <a href="https://www.sitepoint.com/foundations-first-four-pillars-every-enterprise-needs-before-ai/?ref=docupoint.eu" rel="noopener nofollow">standardized data, an architecture built to support AI rather than tolerate it, governance that can explain what happened and catch problems early, and teams that collaborate instead of throwing work over the wall</a>. Get those in place and the model almost takes care of itself. Skip one and you feel it eventually.</p><p>For a small or medium business the licence trap has a particular shape, and it usually wears a Copilot badge. The offer is genuinely tempting: bolt a capable assistant onto the tools your team already uses, pay per head, done. And for an individual it does help. The problem is the leap from "a few people find it handy" to "the business is more productive." That leap is the organizational axis, and no per-seat renewal crosses it. The firms that got the leap right did not buy their way across. They picked one repetitive, document-heavy, rules-based process, rebuilt it around the tool, trained the handful of people involved, and measured the result. That is work, and the work is the point.</p><p>None of this argues against buying the tool. The tool is real and useful. It is just the last 10%, the finishing layer on top of the 90% that no vendor can sell you. Treating the licence as the strategy is like buying a treadmill and expecting to be fit because it is now in the house.</p><h2 id="run-the-scan-before-lunch">Run the scan before lunch</h2><p>You can turn the ten-domain map into a rough self-assessment in about twenty minutes. It will not be precise, and it is not meant to be. It is meant to show you which axis is dragging, so your next euro goes where it is short.</p><p>Take two columns. On the left, the six technology domains. On the right, the four organization domains. Score each one from 0 to 3, and be honest, because the only person you fool with a generous score is yourself.</p><p>On the technology side, ask plainly. Can an AI tool reach our important data without a treasure hunt (<strong>data</strong>)? Is that data clean enough that we would trust an answer built on it (<strong>data</strong> again, it earns two questions)? Do our systems connect, or does everything live in its own silo (<strong>integration</strong>)? Does giving AI access to our information widen a security hole we have not thought about (<strong>information security</strong>)? Do we know where this actually runs and whether that is acceptable for our data and our rules (<strong>cloud and hosting</strong>)? Are the models and the apps we have chosen a fit for the job, or just what came bundled (<strong>models</strong> and <strong>applications</strong>)?</p><p>On the organization side, ask harder. Is our AI pointed at a specific business outcome, or are we doing it because everyone else is (<strong>business strategy</strong>)? Will our people actually change how they work, or will they nod and carry on (<strong>organization and culture</strong>)? Does anyone here have real hands-on AI skill, or are we guessing (<strong>AI strategy and experience</strong>)? Can we explain what the AI did, catch it when it goes wrong, and stay inside the rules (<strong>AI governance</strong>)?</p><p>Add up each column. The pattern matters more than the total. A high left and a low right is the shelf of unused licences, and your money should go to workflow redesign and skills, not more tools. A high right and a low left is enthusiasm about to hit a wall, and your effort should go to data and integration before you scale anything. Low on both, which is most businesses, means start small on one process and build both axes together rather than maxing out one.</p><p>The encouraging part, if you are small, is where the single biggest gap sits. Across Europe the most-cited barrier to AI is not budget and not technology. It is <a href="https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises&ref=docupoint.eu" rel="noopener nofollow">a lack of relevant expertise, named by 71% of enterprises</a>. That is an organization-axis gap, and it is one a focused SMB can close without outspending anyone. It is also worth scoring governance honestly rather than treating it as paperwork, because in Europe it is already law: the <a href="https://artificialintelligenceact.eu/article/4/?ref=docupoint.eu" rel="noopener nofollow">EU AI Act has required every organization that uses AI to ensure a basic level of AI literacy among its staff since February 2025</a>. Governance is a readiness domain, not a tax on one.</p><p>This scan is the pocket version. A fuller assessment, the kind that turns a score into a sequenced roadmap, is where this series lands in a later article. For now, the twenty-minute check is enough to stop you spending on the wrong axis.</p><hr><p>Go back to the two companies that bought the same tool in the same quarter. The one that won did not find a better model hiding in the same licence. It moved both axes. It put its data in reach, then it picked one process, redesigned it, trained the people, and measured the result. The one that lost moved a single axis, waited for the other to move by itself, and it never did.</p><p>That is the whole lesson of the two-axis view. Readiness is not a product with a price. It is a balance you strike between the machine and the business around it, and the machine is the easy half. You can buy every licence on the market and still score zero on the axis that carries 70% of the value. Or you can spend almost nothing, fix one workflow, teach four people, and start compounding.</p><p>A pile of licences is not a strategy. It is one pan of the scale, sitting there waiting for you to load the other.</p><p>The next article turns to the domain most companies treat as a brake and the leaders treat as an accelerator: governance and trust. In Europe, with the AI Act now live and data sovereignty in play, getting trust right is not the thing that slows AI down. As the next piece shows, it is the thing that lets you scale it at all.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[The AI Readiness Gap: Why Most European Companies Get Nothing From AI]]></title>
                    <description><![CDATA[In August 2025, a research team at MIT published a number that should have stopped every boardroom AI project cold. After studying more than 300 enterprise deployments, the MIT NANDA initiative found that 95% of enterprise generative-AI pilots delivered no measurable return at all.]]></description>
                    <link>https://www.docupoint.eu/blog/the-ai-readiness-gap-why-most-european-companies-get-nothing-from-ai/</link>
                    <guid isPermaLink="false">6a49fa8dc6f8b40001491418</guid>

                        <category><![CDATA[AI Strategy]]></category>
                        <category><![CDATA[AI-readyness]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sun, 05 Jul 2026 10:53:05 +0200</pubDate>

                        <media:content url="https://images.unsplash.com/photo-1573166826272-5acd0ef8f650?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDY2fHx3aGl0ZWJvYXJkJTIwQUl8ZW58MHx8fHwxNzgzMjQxNDA2fDA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1573166826272-5acd0ef8f650?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDY2fHx3aGl0ZWJvYXJkJTIwQUl8ZW58MHx8fHwxNzgzMjQxNDA2fDA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" alt="The AI Readiness Gap: Why Most European Companies Get Nothing From AI"/> <p>In August 2025, a research team at MIT published a number that should have stopped every boardroom AI project cold. After studying more than 300 enterprise deployments, the MIT NANDA initiative found that <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/?ref=docupoint.eu" rel="noopener nofollow">95% of enterprise generative-AI pilots delivered no measurable return</a>. Not a small return. No measurable return at all.</p><p>The finding landed quietly, then spread through finance departments like cold water. Here were companies that had bought the licenses, run the pilots, sat through the demos, and watched their investment produce nothing they could point to on a profit-and-loss statement.</p><p>If you run a small or medium business in Europe and you have felt that same quiet disappointment with AI, you are not behind. You are in the majority.</p><p><strong>The numbers tell a brutal story.</strong> Independent of any vendor, <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">McKinsey found that only around 39% of organizations report any bottom-line impact from AI, and for most of them the impact is under 5%</a>. Boston Consulting Group put it more bluntly: <a href="https://www.bcg.com/publications/2024/wheres-value-in-ai?ref=docupoint.eu" rel="noopener nofollow">74% of companies show no tangible value from AI at all</a>. Meanwhile a small group pulls away. An IDC study commissioned by Microsoft found that the leading firms earn <a href="https://www.microsoft.com/en-us/worklab/work-trend-index/2025-the-year-the-frontier-firm-is-born?ref=docupoint.eu" rel="noopener nofollow">a 2.84 times return on their AI investment, against just 0.84 times for the laggards</a>.</p><p>This article is about that gap, and about the one thing the winners have that the rest do not. It is not a bigger budget. It is not a better model. It is readiness. And once you understand what readiness actually means, the gap stops looking like a wall and starts looking like an opening.</p><p>Because here is the part the hype merchants leave out: the reason most AI projects fail has almost nothing to do with the AI.</p><h2 id="the-gap-is-real-and-it-is-widening">The gap is real, and it is widening</h2><p>Start with adoption, because the story usually gets told backwards. AI is not rare. Across the EU, <a href="https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20251211-2?ref=docupoint.eu" rel="noopener nofollow">around 20% of enterprises used AI in 2025, up from 13.5% the year before</a>. Denmark leads the entire union at <a href="https://www.dst.dk/nyt/55352?ref=docupoint.eu" rel="noopener nofollow">42%, nearly double its 2024 figure</a>. Look at large companies alone and the numbers climb higher still. Globally, <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report?ref=docupoint.eu" rel="noopener nofollow">88% of organizations now use AI in at least one function</a>.</p><p>So access is not the problem. Almost everyone has touched AI. The problem shows up at the next step, when access is supposed to turn into value.</p><p>That is where the crowd thins out fast. Gartner predicted that <a href="https://www.gartner.com/en/newsroom/press-releases/2024-07-29-gartner-predicts-30-percent-of-generative-ai-projects-will-be-abandoned-after-proof-of-concept-by-end-of-2025?ref=docupoint.eu" rel="noopener nofollow">at least 30% of generative-AI projects would be abandoned after the proof-of-concept stage by the end of 2025</a>. McKinsey counts only about <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">6% of firms as genuine "AI high performers"</a>. BCG counts <a href="https://www.bcg.com/publications/2024/wheres-value-in-ai?ref=docupoint.eu" rel="noopener nofollow">just 26% that have moved past pilots to real, scaled value</a>.</p><p>Put those figures next to each other and a shape appears. A large majority experiments. A thin minority profits. The distance between them grows every year, because the firms that figure it out compound their advantage while everyone else restarts the same failed pilot with a newer model.</p><p>For European SMBs the shape is sharper still. The <a href="https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises&ref=docupoint.eu" rel="noopener nofollow">gap between large and small firms is enormous: 55% of big EU companies use AI, against 17% of small ones</a>. The union has set itself a target of <a href="https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Towards_Digital_Decade_targets_for_Europe&ref=docupoint.eu" rel="noopener nofollow">75% of enterprises using AI, cloud, or big data by 2030</a>, and on current trends AI is the piece dragging behind. That target will be won or lost in the small and medium businesses that make up most of the European economy.</p><div class="kg-card kg-header-card kg-v2 kg-width-full kg-content-wide " data-background-color="#000000">
            
            <picture><img class="kg-header-card-image" src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/07/88--.png" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/07/88--.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/07/88--.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/07/88--.png 1600w" loading="lazy" alt=""></picture>
        
            <div class="kg-header-card-content">
                
                <div class="kg-header-card-text kg-align-center">
                    
                    
                    
                </div>
            </div>
        </div><h2 id="buying-tools-is-not-the-same-as-being-ready">Buying tools is not the same as being ready</h2><p>Here is the trap almost every company walks into. AI arrives as a product. A licence. A per-seat price. A logo in the corner of software you already use. So it gets treated like any other software purchase: approve the budget, buy the seats, send an email announcing the rollout, and wait for the productivity to appear.</p><p>It does not appear. The licences sit mostly unused, the pilot quietly winds down, and a year later someone in finance asks what the return was.</p><p>The MIT researchers who found that 95% failure rate were clear about the cause. The pilots did not fail because the models were weak. They failed because of how companies tried to use them. Value showed up when firms rebuilt a specific workflow around the tool, and stayed absent when they simply bolted the tool onto how they already worked.</p><p>BCG reached the same conclusion from a different angle and turned it into a rule of thumb. In the companies that actually get value from AI, <a href="https://www.bcg.com/press/30september2025-ai-leaders-outpace-laggards-revenue-growth-cost-savings?ref=docupoint.eu" rel="noopener nofollow">only about 10% of the effort goes into algorithms and models, 20% into technology and data, and a full 70% into people and process</a>. The maths is uncomfortable for anyone hoping to buy their way to readiness. The part you can purchase is the small part. The part that decides whether it works is the part no vendor can sell you.</p><p>Gartner's data points the same direction. The organizations most satisfied with their AI results were the ones that <a href="https://www.gartner.com/en/articles/genai-project-failure?ref=docupoint.eu" rel="noopener nofollow">spent roughly 30% more on data, governance, and talent</a>, not on models. And <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk?ref=docupoint.eu" rel="noopener nofollow">63% of organizations either lack the right data management practices for AI or are not sure whether they have them</a>. A brilliant model pointed at disorganized data produces confident nonsense, faster.</p><p>None of this is a reason to avoid AI. It is a reason to stop treating a Copilot licence as a strategy. The tool is real and useful. It is just the last 10%, not the first step.</p><h2 id="what-the-few-actually-do-differently">What the few actually do differently</h2><p>So what separates the firms that get the 2.84 times return from the ones that get nothing? Strip away the vendor language and it comes down to two things working together, not one.</p><p>The first is technical. The winners have their data in order, their systems connected, and somewhere sensible for the work to happen. Not perfect, but organized enough that an AI tool can reach clean information and act on it.</p><p>The second is organizational, and this is the one almost everyone underweights. The winners changed how work gets done. They picked a real process, redesigned it around the new capability, retrained the people involved, and measured whether it actually helped. McKinsey found that the high performers were far more likely to <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=docupoint.eu" rel="noopener nofollow">fundamentally redesign workflows rather than sprinkle AI on top of the old ones</a>.</p><p>Readiness is those two axes together. Strong technology and a stalled organization gets you an expensive pilot that nobody adopts. A motivated organization on top of chaotic data gets you enthusiasm that hits a wall. You need both, and most companies are unbalanced on one side or the other. That balance is important enough that it deserves its own article, which is where this series goes next.</p><p>The encouraging part, especially if you are small, is what this list does not include. It does not require a hyperscaler budget. It does not require a data-science team. The single most cited barrier to AI across Europe is not cost or technology. It is <a href="https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises&ref=docupoint.eu" rel="noopener nofollow">a lack of relevant expertise, named by 71% of enterprises</a>. That is a skills-and-organization gap. Which means it is a gap an SMB can close with focus, without outspending anyone.</p><h2 id="what-this-means-if-you-are-an-smb-on-a-real-budget">What this means if you are an SMB on a real budget</h2><p>If you are a European small or medium business, the readiness gap is not bad news. It is the most level playing field AI will ever offer you, for three reasons.</p><p>First, the winning ingredients are mostly organizational, and small companies are better at organizational change than large ones. You do not need to align twelve departments and a global IT function. You need to fix one workflow and get a handful of people to work differently. That is a Tuesday for a well-run SMB and a two-year programme for an enterprise.</p><p>Second, you can start where the value is highest and the risk is lowest. The firms getting results did not begin with a moonshot. They took one repetitive, document-heavy, rules-based process, the kind every business has, and rebuilt it. Pick the task your team complains about most. Start there.</p><p>Third, doing it properly in Europe means doing it in a way that respects the rules from day one, and that is easier when you are small and starting fresh than when you are large and retrofitting. The <a href="https://artificialintelligenceact.eu/article/4/?ref=docupoint.eu" rel="noopener nofollow">EU AI Act already requires every organization that uses AI to ensure its staff have a basic level of AI literacy, a duty that has been in force since February 2025</a>. Your data-protection obligations under GDPR do not pause because a tool is clever. Building with governance in mind from the start is not a tax on readiness. As this series will show, it is part of what makes the readiness real. That is the subject of a later article, on why trust is the accelerator rather than the brake.</p><p>The honest summary is this. AI will not transform your business because you bought it. It will transform your business if you change how your business works, in one place, on purpose, and then in another. The tool is the easy part. The readiness is the work. And the work is squarely within reach of a company your size.</p><hr><p>The MIT number that opened this article, the 95% of pilots that returned nothing, was not a verdict on artificial intelligence. It was a verdict on how companies approached it. The 5% that worked were not using secret models. They were using the same tools as everyone else, wrapped around a business that had made itself ready to use them.</p><p>That is the whole game. Not the model. Not the licence. The readiness underneath. Most European companies still have it backwards, spending on the tool and skipping the work, then wondering why the return never comes.</p><p>The good news is that the recipe is not a mystery, and it is not reserved for the giants. It is two axes, balanced, applied to one process at a time. In the next article we take the first of those axes apart, and explain why readiness is something you build, not something you buy.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[1984 → 2048: Den fjerde vej]]></title>
                    <description><![CDATA[Modsat Winston Smith har Europa demokratiske institutioner, regulatorisk magt og 450 millioner borgere som stadig valg vælge. ]]></description>
                    <link>https://www.docupoint.eu/da/1984-2048-den-fjerde-vej/</link>
                    <guid isPermaLink="false">69b1e43414da570001b327b2</guid>

                        <category><![CDATA[Digital Trust Wars]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[chat-control]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 04 May 2026 08:00:00 +0200</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221045.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221045.png" alt="1984 → 2048: Den fjerde vej"/> <p><em>Del 3 af 3 i trilogien "1984 → 2048: Europas valg"</em></p><p>Danmarks justitsminister stod ved en talerstol i København og sagde den stille del højt:</p><blockquote>Vi skal bryde med den helt fejlagtige opfattelse, at det er en borgerrettighed for alle at kommunikere på krypterede beskedtjenester.</blockquote><p>Læs det igen. En siddende dansk minister, ikke kinesisk, ikke russisk, <strong><em>europæisk</em></strong>, erklærede, at privat kommunikation ikke er en grundlæggende rettighed.</p><p>Lige præcis her, er hvad den advarsel handlede om:</p><p>I 1984 er O'Brien det Indre Parti-medlem, der torturerer Winston til at elske Big Brother. Han skjuler ikke, hvad Partiet er. Han forklarer det: <em>"We are not interested in the good of others; we are interested solely in power."</em></p><p>Peter Hummelgaard er Europas O'Brien. Og i modsætning til Orwells fiktion er han virkelig, han har magten, og han fortæller dig præcis, hvad han har til hensigt at gøre.</p><p>I <a href="https://www.docupoint.eu/da/1984-2048-de-tre-digitale-supermagter/" rel="noreferrer">Del 1</a> blev de tre digitale superstater kortlagt. I <a href="https://www.docupoint.eu/da/1984-2048-europa-under-belejring/" rel="noreferrer">Del 2</a> blev det dokumenteret, hvordan Europa er under belejring. Nu kommer det spørgsmål, der virkelig betyder noget: <strong>Findes der en fjerde vej, eller vil Europa blive det, det hævder at bekæmpe?</strong></p><p>Europa besidder noget, Winston Smith aldrig havde: fungerende demokratiske institutioner, reguleringsmagt der bider, og 450 millioner borgere der kan vælge. Spørgsmålet er ikke, om modstand er mulig. Spørgsmålet er, om Europa vil bruge, hvad det har. Eller om det selv vil bygge overvågningsstaten.</p><p>Klokken slår tretten, og klokkeslagene kommer indefra huset.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Pasted-image-20260106221045.png" class="kg-image" alt="Klokken slår tretten" loading="lazy" width="1243" height="723" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/03/Pasted-image-20260106221045.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/03/Pasted-image-20260106221045.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Pasted-image-20260106221045.png 1243w" sizes="(min-width: 720px) 720px"></figure><h2 id="europas-modstand-det-winston-ikke-kunne-have">Europas modstand: det Winston ikke kunne have</h2><p>I 1984 er der ingen modstand. Broderskabet viser sig at være en fiktion skabt af Partiet. Emmanuel Goldstein, Partiets officielle fjende nr. 1 og den angivelige leder af modstanden, eksisterer måske ikke — han kan være opfundet som lokkedue for at afsløre dissidenter. Prolerne holdes for uvidende og underholdte til at gøre oprør. Håb er en illusion, som Partiet fremstiller for at identificere dissidenter.</p><h3 id="demokratiske-institutioner-ufuldkomne-men-virkelige">Demokratiske institutioner: ufuldkomne, men virkelige</h3><p>Winston levede under en etpartistat, hvor valg var teater, og domstole var terrorinstrumenter. Europæere lever under demokratier, hvor regeringer kan stemmes ud. Hvor domstole kan underkende overvågningslove, som <a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2014-04/cp140054en.pdf?ref=docupoint.eu">EU-Domstolen gjorde med Datalagringsdirektivet</a>. Borgere kan sagsøge virksomheder og vinde, som <a href="https://noyb.eu/en/project/schrems-vs-facebook?ref=docupoint.eu">Max Schrems gjorde mod Facebook</a>, to gange. Tilsynsmyndigheder kan pålægge bøder i milliardklassen, som med <a href="https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fine-facebook-result-edpb-binding-decision_en?ref=docupoint.eu">Metas GDPR-bøde på 1,2 milliarder euro</a> i 2023.</p><p>Disse institutioner er ufuldkomne og langsomme, nogle gange fanget af de interesser, de burde regulere. Men de eksisterer.</p><h4 id="reguleringsmagt-effekten-fra-bruxelles">Reguleringsmagt: Effekten fra Bruxelles</h4><p>Europa har noget, ingen anden blok besidder: magten til at sætte globale standarder gennem markedsadgang. "<a href="https://www.cambridge.org/core/books/brussels-effect/DC04DEB2ED4D068D27F20B58B25E5263?ref=docupoint.eu">Brussels Effect</a>" betyder, at virksomheder, der vil have adgang til 450 millioner forbrugere, skal overholde europæiske regler. Ofte anvender de disse regler globalt i stedet for at vedligeholde separate systemer.</p><p>Denne magt har allerede omformet den digitale verden. <a href="https://gdpr.eu/?ref=docupoint.eu">GDPR</a> fra 2018 tvang globale privatlivspolitikker til at blive bedre. Californiens CCPA og Brasiliens LGPD følger dens model. <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-services-act-package?ref=docupoint.eu">Digital Services Act</a> fra 2024 kræver, at platforme adresserer ulovligt indhold, algoritmisk gennemsigtighed og forskeres adgang. <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=docupoint.eu">AI Act</a>, også fra 2024, blev verdens første omfattende AI-regulering. Den forbyder social scoring, begrænser ansigtsgenkendelse og kræver gennemsigtighed for højrisikosystemer. <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-markets-act?ref=docupoint.eu">Digital Markets Act</a> tvinger Big Techs "gatekeepers" til at åbne deres platforme, tillade interoperabilitet og stoppe selvbegunstigelse.</p><p>Superstaterne kan lobbye mod disse reguleringer. De kan true med gengældelse. De kan forsinke overholdelse. Men de kan ikke ignorere et marked på 17 billioner euro.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221219.png" class="kg-image" alt="Brussels Effect" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106221219.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106221219.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221219.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Brussels Effect: Europas reguleringsmagt som forsvar</span></figcaption></figure><h4 id="450-millioner-mennesker-17-billioner-euro-i-bnp">450 millioner mennesker, 17 billioner euro i BNP</h4><p>Europa er ikke alene, som Winston var.</p><p>Den Europæiske Union repræsenterer 450 millioner mennesker, flere end USA. Et marked stort nok til at sætte globale standarder, hvis det vælger at gøre det, med fælles regulering, fri bevægelighed og en fælles valuta for de fleste medlemmer.</p><p>Det her er ikke en lille nation, der kan tvinges til lydighed. Det er en blok, der kan, hvis den vælger det, bygge sin egen infrastruktur, sætte sine egne standarder og styre sin egen kurs. Spørgsmålet er ikke evne. Det er vilje.</p><h3 id="borgerne-v%C3%A5gner-op">Borgerne vågner op</h3><p>I 1984 skriver Winston: "If there is hope, it lies in the proles." Men prolerne organiserer sig aldrig. Europæiske borgere har allerede gjort det.</p><h4 id="privatlivsbeskyttelse-som-v%C3%A6rdi-ikke-kun-regulering">Privatlivsbeskyttelse som værdi, ikke kun regulering</h4><p>GDPR opstod ikke af et bureaukratisk tomrum. Den opstod af <a href="https://edri.org/?ref=docupoint.eu">årtiers europæisk privatlivsaktivisme</a>, af erindringen om overvågningsstater, både nazistiske og kommunistiske, af en kulturel forståelse af, at privatlivsbeskyttelse ikke handler om "at have noget at skjule". Det handler om retten til et selv, der ikke bliver observeret, målt og gjort til en handelsvare.</p><p>Nylige undersøgelser viser, at denne bevidsthed vokser. <a href="https://www.computerweekly.com/news/366633894/European-governments-opt-for-open-source-alternatives-to-Big-Tech-encrypted-communications?ref=docupoint.eu">45 % af europæiske organisationer</a> øgede deres interesse for digital suverænitetsløsninger mellem 2024 og 2025. <a href="https://www.computerworld.com/article/4064116/a-european-alternative-to-m365-nextcloud-looks-to-capitalize-on-digital-sovereignty-interest.html?ref=docupoint.eu">Nextcloud rapporterer en tredobling</a> i forespørgsler om suveræne cloud-alternativer.</p><h4 id="open-source-som-modstand">Open source som modstand</h4><p>Partiet kontrollerede al teknologi. Europæere kan bygge deres egen.</p><p><a href="https://kitemetric.com/blogs/top-10-european-open-source-projects-to-watch-in-2025?ref=docupoint.eu">Europæiske open source-projekter</a> skaber alternativer til enhver stor amerikansk platform. <a href="https://nextcloud.com/?ref=docupoint.eu">Nextcloud</a> i Tyskland tilbyder selvhostet cloud-lagring, samarbejde og kontorpakke. Det bruges nu af den tyske forbundsregering, det franske undervisningsministerium og tusindvis af europæiske organisationer. <a href="https://matrix.org/?ref=docupoint.eu">Matrix</a> er en decentraliseret, krypteret beskedprotokol, der er blevet adopteret af den <a href="https://element.io/case-studies/tchap?ref=docupoint.eu">franske regering</a>, det tyske forsvar og NATO til sikker kommunikation. <a href="https://joinpeertube.org/?ref=docupoint.eu">PeerTube</a> fra Frankrig tilbyder fødereret videohosting uden tracking, uden reklamer og uden algoritmisk manipulation. <a href="https://joinmastodon.org/?ref=docupoint.eu">Mastodon</a>, også tysk, er et decentraliseret socialt netværk, hvor fødererede servere betyder, at der ikke er noget enkelt punkt for kontrol eller nedbrud.</p><p>Det er produktionsklare alternativer, der bruges af regeringer og virksomheder. De beviser, at suverænitet er teknisk muligt.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221517.png" class="kg-image" alt="Europæiske alternativer eksisterer" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106221517.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106221517.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221517.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Europæiske alternativer eksisterer: Værktøjerne til digital suverænitet er klar</span></figcaption></figure><h4 id="borgere-kr%C3%A6ver-forandring">Borgere kræver forandring</h4><p>Partiet undertrykte al dissens. Det europæiske civilsamfund kæmper imod.</p><p><a href="https://edri.org/?ref=docupoint.eu">European Digital Rights (EDRi)</a> koordinerer et netværk af 44 NGO'er, der forsvarer digitale rettigheder i hele Europa. <a href="https://www.laquadraturedunet.org/en/?ref=docupoint.eu">La Quadrature du Net</a> i Frankrig <a href="https://edri.org/our-work/how-to-fight-biometric-mass-surveillance-after-the-ai-act-a-legal-and-practical-guide/?ref=docupoint.eu">vandt en retssag</a> og stoppede algoritmisk videoovervågning i Grenoble. <a href="https://noyb.eu/?ref=docupoint.eu">noyb (None of Your Business)</a>, Max Schrems' organisation, har indgivet hundredvis af GDPR-klager og vundet skelsættende sager mod Facebook, Google og Amazon.</p><p>Europæiske borgere har allerede organiseret sig.</p><h2 id="klokken-sl%C3%A5r-tretten">Klokken slår tretten</h2><p>Åbningslinjen i 1984: <em>"It was a bright cold day in April, and the clocks were striking thirteen."</em></p><p>Den umulige tid signalerer, at noget er grundlæggende galt. Verden ser normal ud (lys, kold, april), men klokkerne fortæller en sandhed, som bevidste sind har lært at ignorere.</p><p><strong>I 2026 slår klokkerne tretten, og de fleste europæere bemærker det ikke.</strong></p><h3 id="advarselstegn-vi-ignorerer">Advarselstegn vi ignorerer<br></h3><h4 id="ansigtsgenkendelse-forbudt-i-teorien-spredt-i-praksis">Ansigtsgenkendelse: forbudt i teorien, spredt i praksis</h4><p>AI Act <a href="https://www.europarl.europa.eu/news/en/press-room/20240308IPR19015/artificial-intelligence-act-meps-adopt-landmark-law?ref=docupoint.eu">forbyder live-ansigtsgenkendelse på offentlige steder</a> fra februar 2025. Men undtagelserne opsluger reglen: retshåndhævelse kan bruge det til ofre, terrorister og mistænkte for grov kriminalitet. <a href="https://edri.org/our-work/how-to-fight-biometric-mass-surveillance-after-the-ai-act-a-legal-and-practical-guide/?ref=docupoint.eu">Kritikere advarer</a> om, at disse undtagelser er "meget vage." Diego Naranjo fra European Digital Rights kalder det "normaliseringen af masseovervågning."</p><h4 id="intet-at-skjule-som-accepteret-sandhed">"Intet at skjule" som accepteret sandhed</h4><p>Partiets største sejr var at få borgerne til at overvåge sig selv. Den moderne ækvivalent: "Hvis du ikke har noget at skjule, har du intet at frygte."</p><p>Det vender uskyldsformodningen på hovedet. Det antager, at overvågning er neutral. At kun de skyldige har brug for privatlivsbeskyttelse. At overvågerne aldrig misbruger magt.</p><p>Historien skriger det modsatte. <a href="https://www.bstu.de/en/?ref=docupoint.eu">Stasi-arkiverne</a> viste, hvordan "almindelig" overvågning ødelagde liv. <a href="https://www.theguardian.com/world/2013/aug/24/nsa-analysts-abused-surveillance-systems?ref=docupoint.eu">NSA's LOVEINT-skandale</a> afslørede analytikere, der spionerede på kæresteemner.</p><h4 id="chat-control-testsagen">Chat Control: testsagen</h4><p>Denne artikel åbnede med Hummelgaards erklæring. Overvej nu, hvad det betyder i praksis.</p><p><a href="https://edri.org/our-work/chat-control-what-is-actually-going-on/?ref=docupoint.eu">Chat Control-forslaget</a> ville kræve scanning af al privat digital kommunikation, inklusive krypterede beskeder. Den tekniske mekanisme, "client-side scanning", ville kræve, at beskedapps som Signal, WhatsApp og Telegram scanner indhold <em>før</em> kryptering. Det ville reelt <a href="https://www.eff.org/deeplinks/2025/12/after-years-controversy-eus-chat-control-nears-its-final-hurdle-what-know?ref=docupoint.eu">skabe en bagdør ind i enhver privat samtale</a>.</p><p><a href="https://www.eff.org/deeplinks/2025/09/chat-control-back-menu-eu-it-still-must-be-stopped-0?ref=docupoint.eu">Signal Foundation truede med at forlade EU-markedet</a> frem for at overholde kravet. Efterretningstjenester advarede imod det. FN understregede, at underminering af kryptering ville krænke retten til privatliv.</p><p>Begrundelsen skifter, overvågningen er identisk.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222612.png" class="kg-image" alt="Samme overvågning, forskellige flag" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106222612.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106222612.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222612.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Samme overvågning, forskellige flag: Forskellige begrundelser, identiske metoder</span></figcaption></figure><p><a href="https://eutechloop.com/return-of-chat-control/?ref=docupoint.eu">Tyskland stemte i sidste ende imod</a>. <a href="https://dig.watch/updates/denmark-drops-chat-control-proposal-amid-backlash?ref=docupoint.eu">Offentligt pres tvang Danmark til at droppe obligatorisk scanning</a> i slutningen af 2025. Men forslaget fortsætter mod <a href="https://www.eff.org/deeplinks/2025/12/after-years-controversy-eus-chat-control-nears-its-final-hurdle-what-know?ref=docupoint.eu">de afsluttende forhandlinger</a> med "frivillige" scanningskrav, som kritikere advarer om vil blive obligatoriske.</p><p>Den fjerde vej kan ikke bygges på overvågning. I det øjeblik Europa bryder kryptering "for børnenes skyld", mister det den moralske autoritet til at kritisere Amerika for at bryde den "for terrorisme" eller Kina for at bryde den "for stabilitet." Privatlivsbeskyttelse kan ikke deles op, og bagdøre er bagdøre. Når de først er bygget, vil de blive udnyttet.</p><h3 id="hvad-sker-der-hvis-europa-fejler">Hvad sker der, hvis Europa fejler</h3><p>Glem 2084. Hvordan ser 2030 ud, hvis Chat Control vedtages?</p><ul><li>Hvert foto, du sender, scannes før kryptering</li><li>Hver besked analyseres af AI, der markerer "mistænkeligt" indhold</li><li>Din krypterede samtale med din advokat? Ikke krypteret længere</li><li>Signal forlader EU-markedet. Du bruger den kompromitterede app, der er tilbage</li><li>Infrastrukturen eksisterer, og den næste regering, eller den efter den, vil finde nye grunde til at bruge den</li></ul><p>Når overvågningsinfrastruktur først er bygget, bliver den ikke afmonteret. Den bliver udvidet. Den bliver normaliseret.</p><p>Den sidste linje i 1984: <em>"He loved Big Brother."</em></p><p>Winston Smiths nederlag var totalt. Ikke fordi Partiet brækkede hans krop, men fordi det erobrede hans sind.</p><p><strong>Orwell forestillede sig, at totalitarisme ville kræve tortur. Platformene opdagede, at det kun kræver dopamin.</strong></p><p>"We needed to sort of give you a little dopamine hit every once in a while," <a href="https://www.axios.com/2017/11/09/sean-parker-unloads-on-facebook-god-only-knows-what-its-doing-to-our-childrens-brains?ref=docupoint.eu">indrømmede Sean Parker</a>, Facebooks stiftende præsident. "It's a social validation feedback loop... exploiting a vulnerability in human psychology."</p><p>Partiet brugte smerte, platformene bruger nydelse. Algoritmen <a href="https://journals.sagepub.com/doi/10.1177/17579139251331914?ref=docupoint.eu">kaprer belønningskredsløb</a> med variable belønninger. Den samme mekanisme, der gør spillemaskiner vanedannende. Hver notifikation er et træk i håndtaget.</p><p>Partiet var nødt til at bygge en overvågningsstat, vi crowdfundede vores gennem app-køb.</p><p>Big Brother har ikke brug for en teleskærm på din væg. Du købte en, puttede den i lommen og tjekker den 150 gange om dagen.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222359.png" class="kg-image" alt="Dopaminfængslet" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106222359.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106222359.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222359.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Dopaminfængslet: Komfortabelt fangenskab gennem digital afhængighed</span></figcaption></figure><p><strong>Superstaterne erobrer ikke Europas sind gennem invasion, men ét dopaminhit ad gangen.</strong></p><h2 id="hvad-du-kan-g%C3%B8re">Hvad du kan gøre</h2><p>Winston Smith havde ingen muligheder. Du har.</p><h3 id="skift-dine-v%C3%A6rkt%C3%B8jer">Skift dine værktøjer</h3><ul><li>E-mail: <a href="https://proton.me/?ref=docupoint.eu">ProtonMail</a> eller <a href="https://tuta.com/?ref=docupoint.eu">Tuta</a> (europæisk, krypteret)</li><li>Cloud-lagring: <a href="https://nextcloud.com/?ref=docupoint.eu">Nextcloud</a> (europæisk, kan selvhostes)</li><li>Beskeder: <a href="https://signal.org/?ref=docupoint.eu">Signal</a> (så længe det varer i Europa) eller <a href="https://element.io/?ref=docupoint.eu">Element/Matrix</a></li><li>Søgning: <a href="https://www.ecosia.org/?ref=docupoint.eu">Ecosia</a> eller <a href="https://www.qwant.com/?ref=docupoint.eu">Qwant</a> (europæiske alternativer)</li><li>Browser: <a href="https://www.mozilla.org/firefox/?ref=docupoint.eu">Firefox</a> (nonprofit, privatlivsfokuseret)</li></ul><h3 id="kr%C3%A6v-handling">Kræv handling</h3><ul><li>Kontakt dit MEP om Chat Control: <a href="https://www.europarl.europa.eu/meps/en/home?ref=docupoint.eu">europarl.europa.eu/meps</a></li><li>Støt digitale rettighedsorganisationer: <a href="https://edri.org/?ref=docupoint.eu">EDRi</a>, <a href="https://noyb.eu/?ref=docupoint.eu">noyb</a>, <a href="https://www.laquadraturedunet.org/en/?ref=docupoint.eu">La Quadrature du Net</a></li><li>Spørg din arbejdsgiver: Hvor opbevares vores virksomhedsdata? Hvem har adgang? Hvad er vores plan for digital suverænitet?</li></ul><h3 id="hold-dig-informeret">Hold dig informeret</h3><ul><li>Følg Chat Control-forhandlingerne på <a href="https://chatcontrol.eu/?ref=docupoint.eu">chatcontrol.eu</a></li><li>Læs <a href="https://www.eff.org/issues/surveillance?ref=docupoint.eu">EFF's dækning af overvågning</a></li><li>Støt uafhængig europæisk tech-journalistik</li></ul><p>I Orwells verden slog klokken tretten, og ingen bemærkede det.</p><p>I vores verden kan vi stadig høre klokkeslagene, hvis vi kan rive os selv væk fra vores skærme længe nok til at lytte.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[1984 → 2048: Europa under belejring]]></title>
                    <description><![CDATA[Del 2 af 3 i trilogien &quot;1984 → 2048: Europas valg&quot;

&quot;We are not interested in the good of others; we are interested solely in power.&quot; — O&#39;Brien til Winston Smith, 1984

Brexit og Trump kom ikke ud af ingenting. De kom ud af en strategi.]]></description>
                    <link>https://www.docupoint.eu/da/1984-2048-europa-under-belejring/</link>
                    <guid isPermaLink="false">69b1e43514da570001b327ca</guid>

                        <category><![CDATA[Digital Trust Wars]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[Security]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 16 Mar 2026 07:00:01 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" alt="1984 → 2048: Europa under belejring"/> <p><em>Del 2 af 3 i trilogien "1984 → 2048: Europas valg"</em></p><blockquote>"We are not interested in the good of others; we are interested solely in power." — O'Brien til Winston Smith, <em>1984</em></blockquote><p>Brexit og Trump kom ikke ud af ingenting. De kom ud af en strategi.</p><p>Den samme kreds af aktører opererede på begge sider af Atlanten i 2016. Finansieret af de samme donorer, drevet af den samme ideologi, forbundet gennem det samme datafirma. Cambridge Analytica arbejdede for Leave.EU og for Trump-kampagnen. Steve Bannon sad i Cambridge Analyticas bestyrelse og drev Breitbart, før han blev Trumps kampagnechef. Robert Mercer finansierede det hele.</p><p>Parallelt kørte russiske trollefabrikker deres egne operationer på de samme platforme, rettet mod de samme splittelser. Om de to spor var koordinerede eller blot opportunistisk sammenfaldende, er stadig et åbent spørgsmål. Men resultatet var det samme: den angelsaksiske verden blev splittet, og det arsenal af teknikker, der virkede i 2016, er nu rettet mod det europæiske kontinent.</p><p>I <a href="https://www.docupoint.eu/1984-2048-three-digital-superstates/">Del 1</a> blev de tre digitale superstater og deres permanente krig kortlagt. Her vendes blikket mod deres primære slagmark: Europa.</p><p>Kampen om Europa bruger ikke kampvogne og missiler. Den bruger trollefabrikker og bankoverførsler, datadrevet vælgermanipulation og kaprede platforme. Rusland har brugt et årti på at dyrke højreekstreme bevægelser over hele kontinentet. Amerika har opbygget en overvågningsinfrastruktur, der behandler europæiske data som en ressource, der skal udvindes. Kina fremstiller den hardware, der muliggør begge dele.</p><p>Men Europas største sårbarhed er ikke superstaternes aggression. Det er Europas egen digitale naivitet. Kontinentet, der opfandt privatlivets fred som en menneskeret, har gjort sig fuldstændig afhængigt af udenlandske platforme, udenlandsk hardware og udenlandske cloudtjenester.</p><p>I Orwells <em>1984</em> eksisterer Europa ikke. Det er blevet opslugt: vest ind i Oceanien, øst ind i Eurasien. Den opsluging sker nu, i realtid, gennem mekanismer, Orwell aldrig forestillede sig.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" class="kg-image" alt="The Siege Begins" loading="lazy" width="1239" height="738" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220457.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220457.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png 1239w" sizes="(min-width: 720px) 720px"></figure><h2 id="to-parallelle-spor-bannon-kredsen-og-kreml">To parallelle spor: Bannon-kredsen og Kreml</h2><h3 id="sporet-der-startede-indefra">Sporet der startede indefra</h3><p>2016 var ikke primært et russisk angreb på vestlige demokratier. Det var et indenlandsk projekt, der udnyttede de samme digitale sårbarheder, som Rusland senere forstærkede.</p><p>Personkredsen er dokumenteret: Robert Mercer, milliardær og hedgefond-forvalter, finansierede både <a href="https://en.wikipedia.org/wiki/Breitbart_News?ref=docupoint.eu">Breitbart News</a> og <a href="https://en.wikipedia.org/wiki/Cambridge_Analytica?ref=docupoint.eu">Cambridge Analytica</a>. Steve Bannon sad i Cambridge Analyticas bestyrelse, drev Breitbart som redaktør, og lancerede Breitbart London i 2014 som en platform for den europæiske højrefløj. Samme Bannon blev Trumps kampagnechef i august 2016 og derefter chefstrateg i Det Hvide Hus.</p><p>Cambridge Analytica brugte psykografisk profilering baseret på data fra millioner af Facebook-brugere til at målrette politiske budskaber. Firmaet arbejdede for Leave.EU-kampagnen i Storbritannien og derefter for Trump-kampagnen i USA. Den samme personkreds, de samme teknikker, det samme mål: at mobilisere utilfredse vælgere mod det etablerede system.</p><p>Det er ikke en konspirationsteori. Det er en dokumenteret personkreds med en dokumenteret strategi. Breitbart, Cambridge Analytica, Leave.EU, Trump-kampagnen. Bundet sammen af de samme penge og de samme mennesker.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">💡</div><div class="kg-callout-text">Bannon-Mercer-kredsen: hvem er de?<br><br>I 2016 opererede den samme personkreds bag både Brexit- og Trump-kampagnerne. Det er dokumenteret i virksomhedsregistre, FEC-donationer og vidneudsagn for det britiske parlament.<br><br><b><strong style="white-space: pre-wrap;">Robert Mercer</strong></b> — Milliardær og medstifter af hedgefonden Renaissance Technologies. Investerede <a href="https://en.wikipedia.org/wiki/Cambridge_Analytica?ref=docupoint.eu">$15 millioner i Cambridge Analytica</a> og <a href="https://www.washingtonpost.com/graphics/politics/mercer-bannon/?ref=docupoint.eu">$10 millioner i Breitbart News</a>. Siden 2006 har Mercer-familien doneret over $34 millioner til republikanske kampagner. I 2017 trådte han tilbage fra Renaissance Technologies efter offentligt pres.<br><br><b><strong style="white-space: pre-wrap;">Rebekah Mercer</strong></b> — Roberts datter og netværkets operatør. Bestyrelsesmedlem i Cambridge Analytica, medlem af Trumps overgangsteam i 2016, og direktør i <a href="https://en.wikipedia.org/wiki/Emerdata_Limited?ref=docupoint.eu">Emerdata Limited</a>, det selskab der overtog Cambridge Analyticas aktiver efter skandalen.<br><br><b><strong style="white-space: pre-wrap;">Steve Bannon</strong></b> — Forbindelsesleddet. Sad i Cambridge Analyticas bestyrelse, drev Breitbart News som redaktør (inkl. <a href="https://en.wikipedia.org/wiki/Breitbart_News?ref=docupoint.eu">Breitbart London</a> fra 2014), introducerede Cambridge Analytica til Leave.EU-kampagnen, og blev Trumps kampagnechef i august 2016. Beskrev selv Breitbart som <a href="https://www.washingtonpost.com/graphics/politics/mercer-bannon/?ref=docupoint.eu">"platformen for alt-right"</a>.<br><br><b><strong style="white-space: pre-wrap;">Cambridge Analytica</strong></b> — Datterselskab af britiske SCL Group. Brugte psykografisk profilering baseret på data fra op til <a href="https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal?ref=docupoint.eu">87 millioner Facebook-brugere</a>, høstet uden samtykke gennem forsker Aleksandr Kogans app "This Is Your Digital Life". Arbejdede for Leave.EU-kampagnen og for Trump-kampagnen (betalt <a href="https://campaignlegal.org/update/newly-published-cambridge-analytica-documents-show-unlawful-support-trump-2016?ref=docupoint.eu">$6 millioner via FEC-optegnelser</a>). Lukkede i maj 2018 efter whistlebloweren <a href="https://en.wikipedia.org/wiki/Christopher_Wylie?ref=docupoint.eu">Christopher Wylies</a> afsløringer.<br><br><b><strong style="white-space: pre-wrap;">Hvad der er bevist:</strong></b> Personkredsen, pengene og de organisatoriske forbindelser er dokumenterede. At de samme mennesker og det samme firma opererede på begge sider af Atlanten i 2016, er ikke omstridt.<br><br><b><strong style="white-space: pre-wrap;">Hvad der er omstridt:</strong></b> Cambridge Analyticas faktiske effektivitet. Firmaet hævdede selv æren for Trumps sejr, men Trumps digitale direktør kaldte deres rolle "beskeden", og firmaet indrømmede senere, at det <a href="https://www.nbcnews.com/politics/politics-news/cambridge-analytica-s-effectiveness-called-question-despite-alleged-facebook-data-n858256?ref=docupoint.eu">aldrig brugte psykografisk profilering i Trump-kampagnen</a>. Direkte koordinering med Kreml er ikke fundet i nogen undersøgelse.</div></div><h3 id="det-russiske-spor">Det russiske spor</h3><p>Parallelt med Bannon-kredsens indenlandske operationer kørte Rusland sin egen kampagne.</p><p>Den <a href="https://www.dni.gov/files/documents/ICA_2017_01.pdf?ref=docupoint.eu">amerikanske efterretningsvurdering fra januar 2017</a> konkluderede med "høj tillid", at Ruslands præsident Vladimir Putin "beordrede en påvirkningskampagne" rettet mod det amerikanske valg i 2016. <a href="https://www.justice.gov/archives/sco/file/1373816/download?ref=docupoint.eu">Mueller-rapporten</a> dokumenterede "omfattende og systematisk" indblanding fra Internet Research Agency, som skabte falske amerikanske profiler på sociale medier og organiserede fysiske demonstrationer på begge sider af splittende emner.</p><p>Ruslands tilgang er en blanding af doktrin, opportunisme og institutionaliseret kapacitet. Russiske militærteoretikere har længe beskrevet, hvordan <a href="https://www.lawfaremedia.org/article/russias-far-right-campaign-europe?ref=docupoint.eu">informationskrig, politisk undergravning og strategisk tvetydighed</a> kan opnå mål, som konventionel militærmagt ikke kan. Ikke en detaljeret slagplan, men en tilgang, der udnytter muligheder, når de opstår. Målet er konsistent: at svække NATO og EU's sammenhængskraft.</p><p><strong>Tidslinjen:</strong></p><ul><li><strong>2014: Krim</strong> — Rusland annekterer Krim, mens Vesten reagerer med sanktioner, men ingen militær intervention. Budskabet: Vesten er splittet og vil ikke kæmpe.</li><li><strong>2016: Brexit og Trump</strong> — Internet Research Agency kører <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">samtidige påvirkningskampagner på tværs af vestlige demokratier</a>, parallelt med Bannon-kredsens indenlandske operationer.</li><li><strong>2022: Ukraine</strong> — Fuldskala invasion med væddemålet om, at et splittet Vesten ville gå i opløsning under økonomisk pres.</li></ul><p>De to spor behøver ikke at have været koordinerede for at have været gensidigt forstærkende. Bannon-kredsen skabte splittelsen. Rusland forstærkede den. Platformene muliggjorde begge dele.</p><h3 id="den-europ%C3%A6iske-front-hvad-der-er-dokumenteret">Den europæiske front: hvad der er dokumenteret</h3><h4 id="trollefabrikkerne-bliver-kontinentale">Trollefabrikkerne bliver kontinentale</h4><p>Internet Research Agencys operationer var rettet mod både det amerikanske valg i 2016 og den britiske Brexit-afstemning samtidig. Den samme Sankt Petersborg-baserede trollefabrik kørte <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">samtidige påvirkningskampagner på tværs af vestlige demokratier</a>, skabte falske profiler, forstærkede splittende indhold og organiserede fysiske arrangementer på begge sider af Atlanten.</p><h4 id="f%C3%B8lg-pengene">Følg pengene</h4><p>Russisk finansiering af europæiske partier er dokumenteret af <a href="https://www.lawfaremedia.org/article/russias-far-right-campaign-europe?ref=docupoint.eu">Europa-Parlamentets "Tip of the Iceberg"-rapport</a>. Det franske Front National (nu RN) modtog <a href="https://www.opendemocracy.net/en/5050/russia-ukraine-war-putin-europe-far-right-funding-conservatives/?ref=docupoint.eu">11 millioner euro i lån fra russiske banker i 2014</a>. Østrigs FPO undertegnede en <a href="https://theconversation.com/unmarred-by-russian-spying-scandal-austrias-far-right-expected-to-cruise-to-victory-in-european-elections-231464?ref=docupoint.eu">formel "venskabsaftale" med Putins parti Forenet Rusland i 2016</a>. Pengesporet er dokumenteret.</p><h4 id="den-tyske-forbindelse">Den tyske forbindelse</h4><p>AfD-Kreml-forbindelserne omfatter dokumenterede møder mellem partifolk og russiske aktører. I 2024 blev MEP Maximilian Krah <a href="https://www.washingtonpost.com/world/2024/06/03/russia-europe-far-right-espionage/?ref=docupoint.eu">tilbageholdt og afhørt af FBI</a> under mistanke om at have modtaget Kreml-midler gennem Voice of Europe-operationen. Tysk efterretningstjeneste fortsætter med at overvåge disse kontakter.</p><h4 id="fanget-p%C3%A5-kamera">Fanget på kamera</h4><p>Ibiza-skandalen i 2019 fangede Østrigs FPO-vicekansler på video, mens han diskuterede politiske donationer med en person, der hævdede at være niece til en russisk oligark. Optagelserne <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">afslørede iveren efter Kreml-penge på de højeste niveauer</a> i europæisk politik. Vicekansleren trak sig inden for få dage.</p><h4 id="hvad-der-forbliver-ubevist">Hvad der forbliver ubevist</h4><p>Den direkte forbindelse mellem Bannon/Mercer-kredsen og Kreml er ikke dokumenteret til en retslig standard. Cambridge Analyticas rolle i Brexit er stadig omstridt. Den britiske Information Commissioners undersøgelse fandt "ingen væsentlige brud" fra firmaet i forbindelse med Brexit-afstemningen. At de samme teknikker og den samme personkreds opererede på begge sider af Atlanten, er dokumenteret. At det var koordineret med Moskva, er det ikke.</p><p>Man bør være forsigtig med at se én stor sammensværgelse, hvor der kan være tale om flere uafhængige aktører, der udnytter de samme sårbarheder med de samme værktøjer. Det gør ikke truslen mindre reel. Det gør den sværere at forsvare sig mod.</p><h3 id="h%C3%B8jredrejningen-hvad-der-fulgte">Højredrejningen: hvad der fulgte</h3><p>Siden 2020 har det samme mønster udspillet sig i Europas største demokratier.</p><h4 id="tyskland-det-ut%C3%A6nkelige-vender-tilbage">Tyskland: det utænkelige vender tilbage</h4><p>AfD vandt <a href="https://moderndiplomacy.eu/2025/03/07/shifting-tides-the-far-rights-rise-and-germanys-electoral-dilemma/?ref=docupoint.eu">20,8% ved forbundsdagsvalget i 2025</a>, deres bedste resultat nogensinde. I september 2024 blev Thüringen stedet for den <a href="https://moderndiplomacy.eu/2025/03/07/shifting-tides-the-far-rights-rise-and-germanys-electoral-dilemma/?ref=docupoint.eu">første højreekstreme sejr ved et delstatsvalg i Tyskland siden Anden Verdenskrig</a>. Partileder Alice Weidel har <a href="https://www.dailysabah.com/world/europe/germanys-far-right-afd-vows-to-part-ways-with-eu-paris-deal-euro?ref=docupoint.eu">eksplicit nævnt Brexit som model for "Dexit"</a>, Tysklands udtrædelse af EU. Samtidig advarer tysk efterretningstjeneste om <a href="https://www.washingtonpost.com/world/2024/06/03/russia-europe-far-right-espionage/?ref=docupoint.eu">fortsat russisk dyrkning af AfD-kontakter</a>. Partiet, der engang virkede som en marginal protestbevægelse, former nu den nationale debat.</p><h4 id="frankrig-le-pens-lange-march">Frankrig: Le Pens lange march</h4><p>Marine Le Pens Rassemblement National vandt <a href="https://www.euronews.com/my-europe/2024/06/09/france-marine-le-pens-far-right-party-makes-historic-gains-in-eu-elections?ref=docupoint.eu">31,4% ved Europa-Parlamentsvalget i 2024</a>, deres højeste andel siden 1984. Partiet har nu <a href="https://en.wikipedia.org/wiki/National_Rally?ref=docupoint.eu">125 pladser i Nationalforsamlingen</a> efter lynvalget i juli 2024. Le Pen selv er i øjeblikket <a href="https://www.britannica.com/biography/Marine-Le-Pen?ref=docupoint.eu">udelukket fra præsidentvalget i 2027</a> på grund af en dom for underslæb med EU-midler, men bevægelsen, hun byggede, har sluttet sig til <a href="https://europrospects.eu/patriots-for-europe-a-radical-right-shift-in-the-eus-political-landscape/?ref=docupoint.eu">Patriots for Europe-gruppen</a> sammen med ungarske Fidesz og østrigske FPO og danner dermed en kontinental blok.</p><h4 id="%C3%B8strig-gennem-spejlet">Østrig: gennem spejlet</h4><p>FPO vandt <a href="https://www.euronews.com/2025/01/06/austrias-president-tasks-far-right-fpo-leader-herbert-kickl-with-forming-new-government?ref=docupoint.eu">28,8% ved parlamentsvalget i 2024</a>, deres bedste resultat i historien. <a href="https://www.euronews.com/2025/01/06/austrias-president-tasks-far-right-fpo-leader-herbert-kickl-with-forming-new-government?ref=docupoint.eu">Herbert Kickl er blevet bedt om at danne Østrigs første højreekstremt ledede regering siden Anden Verdenskrig</a>. En tidligere efterretningschef advarede om, at FPO i regering ville være <a href="https://neweasterneurope.eu/2025/02/06/austrias-drift-toward-isolation-kickls-russia-ties-and-the-risk-of-following-hungarys-lead-in-the-war/?ref=docupoint.eu">"et betydeligt sikkerhedsproblem" for internationale partnere</a>. Partiet opretholder <a href="https://theconversation.com/unmarred-by-russian-spying-scandal-austrias-far-right-expected-to-cruise-to-victory-in-european-elections-231464?ref=docupoint.eu">dokumenterede forbindelser til Rusland</a>, selv om de hævder, at deres "venskabstraktat" med Putins Forenet Rusland er udløbet.</p><h3 id="m%C3%B8nstret-eu-kritisk-men-ikke-eu-exit">Mønstret: EU-kritisk, men ikke EU-exit</h3><p>Det, der gør den nuværende drejning strategisk sofistikeret, er, at disse partier <a href="https://carnegieendowment.org/research/2024/04/charting-the-radical-rights-influence-on-eu-foreign-policy?ref=docupoint.eu">ikke længere eksplicit kræver EU-udtrædelse</a>. De lærte af Brexits kaos. I stedet går de ind for et "Europa af suveræne nationer" frem for føderalisme og kræver "national fortrinsret" for egne borgere over EU-borgere. De presser på for undtagelser fra fælles politikker om asyl, klima og forsvar. De hævder national rets forrang over EU-ret trods traktatbrud. Og de arbejder for at blokere yderligere EU-integration og udvidelse ved enhver lejlighed.</p><p>Det er 1984-strategien tilpasset 2026: man behøver ikke fysisk at erobre territorium, hvis man kan udhule institutionerne indefra.</p><h3 id="kausalitet-versus-korrelation">Kausalitet versus korrelation</h3><p>Er den europæiske højredrejning forårsaget af udenlandsk indblanding, eller udnytter udenlandske aktører blot eksisterende utilfredshed? Det ærlige svar: begge dele, og forskellen betyder mindre, end man gerne vil tro.</p><p>Spørgsmålet "hvem startede det?" er måske det forkerte spørgsmål. Bannon-kredsen viste, at vestlige demokratier kunne flyttes med datadrevet manipulation og kulturkrig. Rusland viste, at udenlandske aktører kunne operere frit på de samme platforme. Begge udnyttede reel utilfredshed, som eksisterede uafhængigt af dem.</p><p>Det, der bør bekymre Europa, er ikke hvem der trak i snorene i 2016. Det er, at mekanismerne stadig fungerer. De partier, der er mest på linje med russiske interesser, <a href="https://time.com/7301526/europe-far-right-momentum/?ref=docupoint.eu">vinder magt over hele kontinentet</a>. De platforme, der muliggør manipulation, er stadig amerikanske. Og Europa har stadig ikke bygget alternativer.</p><p><em>I 1984 erobrede Big Brother med magt. I 2026 kan erobringen ske via stemmesedlen, og de fleste vælgere vil aldrig vide, hvem der formede de budskaber, der formede deres holdninger.</em></p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220637.png" class="kg-image" alt="The Rightward March" loading="lazy" width="1200" height="738" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220637.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220637.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220637.png 1200w" sizes="(min-width: 720px) 720px"></figure><h2 id="den-egentlige-s%C3%A5rbarhed-europ%C3%A6isk-digital-naivitet">Den egentlige sårbarhed: europæisk digital naivitet</h2><p>Her er det, europæere må se i øjnene: hverken Rusland eller Bannon-kredsen byggede de våben, de bruger mod os. Vi afleverede dem selv.</p><p>Trollefabrikker og datadrevet manipulation opererer på amerikanske platforme (Facebook, Twitter, YouTube), som Europa adopterede uden at bygge alternativer. Den desinformation, der splitter den europæiske enhed, flyder gennem infrastruktur, vi ikke kontrollerer, styret af algoritmer, vi ikke kan auditere, ejet af virksomheder, der svarer til udenlandske domstole.</p><p>Men <em>hvorfor</em> byggede Europa aldrig sine egne?</p><h3 id="svaret-hedder-tillid-og-det-er-en-tragisk-historie">Svaret hedder tillid. Og det er en tragisk historie.</h3><p>Europa og Amerika har en relation, der går dybere end de fleste forstår. Europa <em>byggede</em> Amerika. Oplysningstankerne, der formede den amerikanske forfatning, kom fra europæiske filosoffer. Millioner af europæere krydsede Atlanten og skabte nationen med deres hænder. Efter Anden Verdenskrig genopbyggede Marshallplanen Europa med amerikanske dollars, men det var europæisk kapital, europæisk viden og europæisk arbejdskraft, der havde bygget den amerikanske økonomi, som nu havde råd til at sende pengene den anden vej.</p><p>Det skabte en relation, der føltes som familie. NATO blev grundlagt i 1949. Amerikanerne stationerede tropper i Europa. Europa delegerede sin sikkerhed til Washington og koncentrerede sig om at bygge velfærdsstater, fællesmarkeder og fredsprojekter. Det var rationelt. Hvorfor bruge penge på forsvar, når din storebror har verdens største militær? Hvorfor bygge egne digitale platforme, når din nærmeste allierede leverer de bedste i verden?</p><p>Europa gav sin bedste ven nøglerne til huset. Adgangskoden til banken. Og alle sine hemmeligheder.</p><p>Det var ikke dumt. Det var tillid. Den slags tillid, man har til familie, hvor man ikke læser det med småt, fordi man ikke forestiller sig, at den anden part ville bruge det mod en.</p><h3 id="s%C3%A5-begyndte-v%C3%A6kningerne">Så begyndte vækningerne</h3><p><strong>2013: Snowden.</strong> Edward Snowden afslører, at NSA har <a href="https://www.theguardian.com/world/2013/oct/23/us-monitored-angela-merkel-german?ref=docupoint.eu">aflyttet Angela Merkels mobiltelefon</a>. Ikke en fjendtlig stats leder. Den tyske forbundskansler. Europas magtfuleste politiker. Aflyttet af sin nærmeste allierede. Europa var rystet. Men Europa gjorde... ingenting strukturelt. Ingen europæiske platforme blev bygget. Ingen cloudinfrastruktur blev omlagt. Tilliden var knækket, men vanerne var intakte. Og hvis Merkel blev aflyttet blev alle aflyttet.</p><p><strong>2016: Trump.</strong> Pludselig sad der en mand i Det Hvide Hus, der kaldte EU en <a href="https://www.bbc.com/news/world-us-canada-44852812?ref=docupoint.eu">"fjende"</a>, behandlede NATO som en beskyttelsesforretning og åbenlyst beundrede Putin. Europa troede, det var en fejl i systemet. Fire år, og så ville den voksne vende tilbage.</p><p><strong>2018: CLOUD Act.</strong> Washington vedtog en <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">lov, der giver amerikanske myndigheder adgang</a> til alle data lagret af amerikanske virksomheder, uanset hvor i verden serverne står. Med ét slag blev enhver europæisk virksomhed, der brugte Microsoft, Google eller Amazon, underlagt amerikansk jurisdiktion. Europa protesterede. Og fortsatte med at bruge de samme tjenester. Problemet med forandringer er at det kræver man forandrer sig.</p><p><strong>2020: Schrems II.</strong> EU-Domstolen <a href="https://curia.europa.eu/juris/liste.jsf?num=C-311/18&ref=docupoint.eu">erklærede Privacy Shield ugyldigt</a>, den aftale, der skulle beskytte europæiske data i amerikanske systemer. Domstolen konkluderede, at amerikansk overvågningslovgivning var uforenelig med europæiske grundrettigheder. Europas højeste ret sagde bogstaveligt: <em>vi kan ikke stole på, at Amerika behandler vores data ordentligt.</em> Men datastrømmene fortsatte.</p><p><strong>2024-2025: Trump vender tilbage.</strong> Og denne gang er det ikke en fejl i systemet. Det <em>er</em> systemet. Toldmure mod europæiske varer. Trusler om at trække sig fra NATO. Åben fjendtlighed mod EU. Det dysfunktionelle familiemedlem, der brænder julepynten af, så snart det ikke får sin vilje.</p><h3 id="advarslerne-var-der-europa-valgte-at-overh%C3%B8re-dem">Advarslerne var der. Europa valgte at overhøre dem.</h3><p>Hvert skridt på vejen var der et øjeblik, hvor Europa kunne have handlet. Kunne have sagt: <em>vi bygger vores egne platforme. Vi lægger vores data på europæiske servere. Vi investerer i europæisk teknologi.</em> I stedet sagde Europa hver gang: <em>det er nok bare et enkelt tilfælde. Alliancen holder. Vi behøver ikke bygge alternativer til vores bedste vens infrastruktur.</em></p><p>Andre regioner var ikke så tillidsfulde. Og de er bedre stillet i dag.</p><p><a href="https://www.theegg.com/seo/korea/search-engine-market-share-in-korea?ref=docupoint.eu">Sydkorea</a>, et land med 51 millioner mennesker, byggede og vedligeholdt sit eget digitale økosystem. <a href="https://www.interad.com/en/insights/korean-search-engine-market-share?ref=docupoint.eu">Naver dominerer søgning med 63% markedsandel</a> (Google har kun 31%). <a href="https://www.meltwater.com/en/blog/korean-social-media?ref=docupoint.eu">KakaoTalk er den universelle beskedapp</a>: stort set alle koreanere bruger den. Naver og Kakao kontrollerer tilsammen <a href="https://admaru.com/2024/02/12/uniqueness-of-the-korean-programmatic-market/?ref=docupoint.eu">over 70% af Koreas digitale annoncemarked</a>.</p><p><a href="https://blog.hubspot.com/marketing/social-media-platforms-that-werent-founded-in-the-us?ref=docupoint.eu">Japan byggede LINE</a> med 186 millioner brugere. <a href="https://globibo.com/et/country-specific-social-media/?ref=docupoint.eu">Rusland har VK</a> og Telegram. <a href="https://www.ecinnovations.com/blog/social-media-around-the-world-20-country-specific-platforms-you-need-to-know-in-2025/?ref=docupoint.eu">Kinas økosystem</a> (WeChat, Weibo, Douyin) er helt hjemligt. Selv Indien, med en endnu mere kaotisk tech-sektor end Europa, byggede <a href="https://en.wikipedia.org/wiki/Unified_Payments_Interface?ref=docupoint.eu">UPI</a>, et betalingssystem, der håndterer 12 milliarder transaktioner om måneden og ikke er afhængigt af Visa eller Mastercard.</p><p>Hvad har disse lande til fælles? De stolede ikke blindt på, at Washington ville handle i deres interesse. Sydkorea er en tæt amerikansk allieret, men det byggede Naver alligevel. Japan har amerikanske baser på sit territorium, men det byggede LINE alligevel. De forstod noget, Europa ikke ville se: at en alliance er et strategisk forhold, ikke et venskab. Og at man aldrig overlader sin infrastruktur til en anden magt, uanset hvor tæt relationen føles.</p><p>Europa med sine 450 millioner mennesker og 17 billioner euro i BNP havde markedskraften til at gøre det samme. Det valgte at stole i stedet.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220830.png" class="kg-image" alt="The Dependency Trap" loading="lazy" width="1248" height="678" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220830.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220830.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220830.png 1248w" sizes="(min-width: 720px) 720px"></figure><p><em>Afhængighedsfælden: 450 millioner mennesker. Nul store platforme.</em></p><h3 id="de-tre-drivkr%C3%A6fter-bag-europ%C3%A6isk-svaghed">De tre drivkræfter bag europæisk svaghed</h3><p><strong>1. Sociale medie-kolonisering.</strong> Europa har ingen store sociale platforme. <a href="https://www.statista.com/statistics/745400/facebook-europe-mau-by-quarter/?ref=docupoint.eu">Facebook har 308 millioner europæiske brugere</a>, <a href="https://newsroom.tiktok.com/en-eu/150-m-people-across-europe-come-to-tiktok-every-month?ref=docupoint.eu">TikTok 150 millioner</a>. Når russiske trolde, kinesiske påvirkningsoperationer eller datadrevne politiske kampagner vil nå europæiske borgere, bruger de platforme, som europæiske myndigheder kan bøde, men ikke fundamentalt kontrollere. DSA er et plaster på et afskåret lem.</p><p><strong>2. Hardwareafhængighed.</strong> Europa designer chips (ASMLs litografimaskiner er essentielle for enhver avanceret processor), men <a href="https://digital-strategy.ec.europa.eu/en/policies/european-chips-act?ref=docupoint.eu">fremstiller næsten ingen</a>. Kinesiske fabrikker bygger telefonerne i europæiske lommer. De overvågningsmuligheder, der er indbygget i hardware, hvad enten det er <a href="https://www.cfr.org/backgrounder/huawei-chinas-controversial-tech-giant?ref=docupoint.eu">kinesiske bagdøre frygtet af vestlig efterretningstjeneste</a> eller <a href="https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order?ref=docupoint.eu">amerikanske afsløret af Snowden</a>, eksisterer i enheder, Europa ikke kan inspicere i stor skala.</p><p><strong>3. Cloudunderkastelse.</strong> Syv ud af ti bytes europæiske data ligger på <a href="https://www.srgresearch.com/articles/european-cloud-providers-continue-to-grow-but-still-lose-market-share?ref=docupoint.eu">amerikanske servere</a>. Europæiske data er underlagt <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">CLOUD Act</a>, tilgængelige for amerikansk efterretningstjeneste, underlagt amerikansk lovgivning. Når Microsoft kan <a href="https://www.politico.eu/article/microsoft-suspends-international-criminal-court-icc-email-services/?ref=docupoint.eu">suspendere Den Internationale Straffedomstols e-mail</a>, og AWS kan <a href="https://www.cnbc.com/2021/01/16/how-parler-deplatforming-shows-power-of-cloud-providers.html?ref=docupoint.eu">deplatforme enhver kunde inden for 24 timer</a>, afsløres europæisk digital suverænitet som en høflig fiktion.</p><h3 id="superstaterne-konkurrerer-om-europa-og-europa-er-s%C3%A5rbart-over-for-dem-alle">Superstaterne konkurrerer om Europa, og Europa er sårbart over for dem alle</h3>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Sårbarhed</th>
<th>Amerikansk udnyttelse</th>
<th>Russisk udnyttelse</th>
<th>Kinesisk udnyttelse</th>
</tr>
</thead>
<tbody>
<tr>
<td>Sociale medier</td>
<td>Platformmonopol, datahøst, algoritmisk kontrol</td>
<td>Desinformationskampagner, politisk manipulation</td>
<td>TikTok-indflydelse, propagandaforstærkning</td>
</tr>
<tr>
<td>Hardware</td>
<td>NSA-tilgængelige enheder, forsyningskædeindflydelse</td>
<td>Begrænset (afhænger af vestlig teknologi)</td>
<td>Produktionsdominans, potentielle bagdøre</td>
</tr>
<tr>
<td>Cloud/data</td>
<td>CLOUD Act-adgang, overvågningsinfrastruktur</td>
<td>Cyberangreb på europæiske systemer</td>
<td>Datakrav for markedsadgang</td>
</tr>
<tr>
<td>Overvågningsmodel</td>
<td>Virksomhedsudvinding ("overvågningskapitalisme")</td>
<td>Statsstyret informationskrig</td>
<td>Stat-virksomhedsfusion, eksporteret globalt</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>Det er ikke en koordineret opdeling. Det er tre uafhængige aktører, der hver udnytter den samme europæiske sårbarhed: afhængighed af infrastruktur, Europa ikke kontrollerer. Spørgsmålet er ikke, om Rusland, Amerika eller Kina udgør den største trussel. Spørgsmålet er, hvorfor Europa byggede en digital civilisation på fundamenter, det ikke kontrollerer.</p><p>Rusland våbengør europæiske sårbarheder. Amerika kommercialiserer dem. Kina producerer den hardware, der muliggør begge dele. Resultatet ligner en belejring, men mekanismen er opportunisme snarere end sammensværgelse, og det gør den sværere at forsvare sig mod.</p><hr><h2 id="europas-1984-mareridt">Europas 1984-mareridt</h2><h3 id="i-orwells-verden-eksisterer-europa-ikke">I Orwells verden eksisterer Europa ikke</h3><p>Det er ikke en metafor. Slå <em>1984</em> op og se på det kort, Orwell tegnede.</p><p>Oceanien omfatter Nord- og Sydamerika, De Britiske Øer, Australasien og det sydlige Afrika. Eurasien strækker sig over hele den eurasiske landmasse fra Portugal til Beringstrædet. Østasien dækker Kina, Japan og Sydøstasien.</p><p>Hvor er Europa?</p><p>Vesteuropa (Frankrig, Tyskland, Benelux, Skandinavien) er en permanent krigszone. Bekriget, men aldrig rigtigt holdt. I romanens baggrundshistorie blev Storbritannien opslugt af Oceanien (den amerikanske sfære) i 1950erne. Kontinentaleuropa faldt til Eurasien (den russiske sfære). Den europæiske civilisation, der gav verden Oplysningstiden, menneskerettighederne og demokratisk styreform, ophørte ganske enkelt med at eksistere som en selvstændig enhed.</p><p>Orwell skrev det i 1948, med fremskrivning til 1984. Han beskrev logikken i supermagtskonkurrence: små og mellemstore magter bliver opslugt eller ødelagt. Der er ikke plads til en tredje vej.</p><p>Testen af, om Orwell tog fejl, udspiller sig lige nu.</p><h3 id="den-nuv%C3%A6rende-kurs-digital-opsluging-i-gang">Den nuværende kurs: digital opsluging i gang</h3><p>Den opsluging, Orwell forestillede sig gennem militær erobring, sker gennem digital afhængighed:</p><ul><li>Europæiske data ligger på amerikanske servere, underlagt amerikansk lovgivning</li><li>Energiafhængigheden var russisk indtil 2022, og rørledningerne kan ikke afmonteres fra den ene dag til den anden</li><li>Telefonen i din lomme er samlet i Kina, af chips designet i Amerika, med software der rapporterer til begge</li><li>Dine politiske holdninger formes af amerikanske algoritmer, forstærkes af russiske operationer og målrettes af datadrevne kampagner, hvis ophav du aldrig ser</li></ul><p>Europa i 2026: fanget mellem tre imperier, sårbart over for dem alle, afhængigt af dem alle.</p><h3 id="den-p%C3%A6ne-version-af-1984">Den "pæne version" af 1984</h3><p>Orwell tog fejl på ét punkt: han antog, at totalitarisme ville være grimt.</p><p>I 1984 hersker Partiet gennem afsavn, frygt og vold. Teleskærmene er obligatoriske. To Minutters Had er tvungent. Værelse 101 bryder kroppen for at erobre sindet. Støvlen tramper på et menneskeansigt, for evigt.</p><p>Men historien lærer os noget andet: imperier bygget på vold falder til sidst. Imperier bygget på begær består.</p><p>Romerne vidste det allerede for 2.000 år siden. Den romerske digter Juvenal beskrev, hvordan det romerske folk, der engang havde kæmpet for politisk indflydelse, stemt om love og holdt magthaverne ansvarlige, var blevet reduceret til at ønske sig to ting: <a href="https://en.wikipedia.org/wiki/Bread_and_circuses?ref=docupoint.eu"><em>panem et circenses</em></a>, brød og cirkus. Giv dem gratis korn og gladiatorkampe, og de glemmer, at de har mistet deres frihed. Mens Colosseum underholdt masserne, kunne kejserne gøre, hvad de ville. Historien fortæller os, at ethvert samfund der bliver undertrykt med vold, ender til sidst med at gøre oprør. Men et samfund, der bliver underholdt til passivitet? Det gør aldrig oprør. Det har for travlt med at scrolle.</p><p>Sovjetunionen faldt, fordi den kun kunne tilbyde støvlen: afsavn, frygt og køer. Den kunne ikke levere det, folk ønskede: forbrugsvarer, frihed, muligheder. Det amerikanske kulturimperium spredte sig gennem <a href="https://www.foreignaffairs.com/articles/united-states/1998-05-01/soft-power?ref=docupoint.eu">cowboybukser, Coca-Cola og Hollywood</a>. Ting, folk selv valgte at omfavne. Man kan ikke opretholde et imperium, der kun tager. De imperier, der varer, er dem, der giver folk, hvad de begærer, og derefter udvinder værdi fra den afhængighed, de skaber.</p><p>Juvenal beskrev Rom. Orwell beskrev Oceanien. Begge tog fejl om formen, men mekanismen er den samme. I 2026 bærer kontrollen et venligere ansigt:</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>1984</th>
<th>2026</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Telescreen</strong> (obligatorisk, overvågede dig)</td>
<td><strong>Smartphone</strong> (frivillig, du købte den, du bærer den overalt)</td>
</tr>
<tr>
<td><strong>Two Minutes Hate</strong> (tvungen forargelse)</td>
<td><strong>Algoritmisk feed</strong> (frivillig forargelse, optimeret for engagement)</td>
</tr>
<tr>
<td><strong>Room 101</strong> (tortur med din dybeste frygt)</td>
<td><strong>Dopaminloops</strong> (belønning med dine dybeste ønsker)</td>
</tr>
<tr>
<td><strong>Newspeak</strong> (ordforrådsreduktion)</td>
<td><strong>Indholdskuratering</strong> (informationsbobler, virkelighedsfragmentering)</td>
</tr>
<tr>
<td><strong>Ministry of Truth</strong> (central propaganda)</td>
<td><strong>Personaliseret virkelighed</strong> (hver bruger ser en anden "sandhed")</td>
</tr>
<tr>
<td><strong>Thought Police</strong> (overvågning for afvigelse)</td>
<td><strong>Prædiktiv analyse</strong> (overvågning for profit og indflydelse)</td>
</tr>
<tr>
<td><strong>Boot on face</strong> (smertefuld kontrol)</td>
<td><strong>Behagelig sneaker</strong> (friktionsfri underkastelse)</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-4.png" class="kg-image" alt="Both images show control" loading="lazy" width="1215" height="745" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/image-4.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/image-4.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-4.png 1215w" sizes="(min-width: 720px) 720px"></figure><p><em>Begge billeder viser kontrol. Kun det ene ansigt ved det.</em></p><p>Partiet forstod, at mennesker kan brydes af smerte. Silicon Valley opdagede, at de kan fanges af nydelse. Resultatet er det samme: en befolkning, der ikke kan tænke klart og ikke kan handle kollektivt.</p><p><strong>Vi tortureres ikke til lydighed. Vi underholdes ind i den.</strong></p><hr><h2 id="doublethink-i-den-digitale-tidsalder">Doublethink i den digitale tidsalder</h2><p>I 1984 betyder "doublethink" at holde to modstridende overbevisninger samtidig og acceptere begge som sande. <em>War is Peace. Freedom is Slavery. Ignorance is Strength.</em></p><p>Hver supermagt praktiserer sin egen version:</p><p><strong>Amerika</strong> erklærer privatlivets fred for en grundlæggende rettighed, mens det driver PRISM, <a href="https://www.theguardian.com/world/2013/oct/23/us-monitored-angela-merkel-german?ref=docupoint.eu">aflytter Angela Merkels telefon</a> og vedtager <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">CLOUD Act</a> for at nå alle data lagret af amerikanske virksomheder, overalt i verden. Regelbaseret international orden, undtagen når amerikanske interesser siger andet.</p><p><strong>Kina</strong> kræver ikke-indblanding i sine interne anliggender, mens det eksporterer overvågningssystemer til <a href="https://freedomhouse.org/report/freedom-net/2023/repressive-power-artificial-intelligence?ref=docupoint.eu">80+ lande</a>. Kameraerne, der overvåger uighurer i Xinjiang, overvåger nu dissidenter i Zimbabwe. Belt and Road lover "win-win-samarbejde". Indtil <a href="https://www.nytimes.com/2018/06/25/world/asia/china-sri-lanka-port.html?ref=docupoint.eu">Sri Lanka mister en havn</a>, og Zambia tilbyder sit elnet som sikkerhed.</p><p><strong>Rusland</strong> hævder, at NATO-udvidelse truer dets sikkerhed, mens det invaderer Georgien, annekterer Krim og indleder fuldskala krig mod Ukraine. Det retfærdiggør invasionen som "afnazificering", mens det <a href="https://www.bbc.com/news/world-europe-65851734?ref=docupoint.eu">anvender Wagner-gruppen</a>, hvis grundlægger bar nazisymboler. Det kræver informationssuverænitet, mens det <a href="https://www.justice.gov/archives/sco/file/1373816/download?ref=docupoint.eu">driver trollefabrikker</a>, der oversvømmer vestlige sociale medier med desinformation.</p><p>For europæere er udfordringen ikke at vælge den "gode" side. Der er ingen god side. Det er måske den sværeste erkendelse af alle: god og ond er ikke kategorier, der eksisterer i geopolitik. Der findes kun interesser.</p><p>Europa er vokset op med en fortælling om, at der findes gode og onde magter, at Vesten er den gode side, at demokrati og markedsøkonomi automatisk producerer retfærdighed. Den fortælling var altid en forenkling, men den fungerede, så længe den amerikanske storebror opførte sig nogenlunde anstændigt.</p><p>Nu er fortællingen brudt sammen. Ikke fordi Amerika pludselig blev "ondt", men fordi sløret er faldet. Supermagter handler ikke ud fra værdier. De handler ud fra afkast. Amerikanske techgiganter overvåger europæere, fordi det er profitabelt. Rusland destabiliserer Europa, fordi et svagt Europa er i Ruslands interesse. Kina eksporterer overvågningsteknologi, fordi der er kunder.</p><p>Der er ingen skurke i denne historie. Kun aktører, der maksimerer deres eget afkast. Og Europa, der troede det handlede om venskab.</p><p>Det er den egentlige doublethink: ikke at 2 + 2 = 5, men at <em>alliance = venskab</em>, at <em>partnerskab = tillid</em>, at <em>fælles værdier = fælles interesser</em>. Europa har accepteret alle tre som sande. Ingen af dem er det.</p><p>Winston Smith blev tvunget til at tro, at 2 + 2 = 5. Europæere har selv valgt at tro, at overvågning er privatlivets fred, at afhængighed er partnerskab, at opsluging er alliance.</p><p>Svaret må være: Nej. Vi kan regne. Og regnestykket viser, at ingen passer vores interesser undtagen os selv.</p><hr><h3 id="kampen-om-europa-er-reel-murene-er-gennembrudt">Kampen om Europa er reel. Murene er gennembrudt.</h3><p>Bannon-kredsen viste, at vestlige demokratier kan manipuleres indefra. Rusland dyrker politikere, der vil udhule EU. Amerika udvinder data gennem platforme, vi ikke kontrollerer. Kina fremstiller de enheder, vi ikke kan inspicere. Og Europa har gjort sig afhængigt af dem alle.</p><p>I Orwells <em>1984</em> spørger Winston Smith O'Brien, hvordan fremtiden ser ud. Svaret: "A boot stamping on a human face, forever."</p><p>Men det var den grimme version. Den version, der avler modstand.</p><p>2026-versionen er anderledes. Støvlen er en behagelig sneaker. Trampet er en blid massage. Menneskeansigtet scroller, altid scroller, for underholdt til at bemærke, hvad det har opgivet.</p><p>Men Europa er ikke Oceanien. Endnu ikke.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[1984 -&gt; 2048: De tre digitale supermagter]]></title>
                    <description><![CDATA[Forstå den digitale krigsførelse, set igennem Orwell&#x27;s 1984 udsyn. Denne artikel undersøger hvordan de 3 digitale superstater, med Amerikas overvågnings kapitalisme, Kina-Ruslands autoritære axe og deres evige digitale krig der omformer den globale magt.]]></description>
                    <link>https://www.docupoint.eu/da/1984-2048-de-tre-digitale-supermagter/</link>
                    <guid isPermaLink="false">69b1e43514da570001b327be</guid>

                        <category><![CDATA[Digital Trust Wars]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[Security]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Fri, 13 Mar 2026 08:00:00 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106085449.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106085449.png" alt="1984 -&gt; 2048: De tre digitale supermagter"/> <p><em>Del 1 af 3 i trilogien "1984 -&gt; 2048: Europas valg"</em></p><p>Du læser dette på en teleskærm.</p><p>Den kender din placering. Den ved, hvem du skrev til i morges. Den ved, hvad du søgte efter i nat, da du ikke kunne sove. Den har fotograferet dit ansigt snesevis af gange i dag og sendt dataene til servere, du aldrig vil se, i lande, hvis love ikke beskytter dig.</p><p>Du betalte godt for den. Du føler dig nøgen uden den.</p><p>George Orwell forestillede sig teleskærmen som et mareridt påtvunget af staten. Han forestillede sig aldrig, at vi frivilligt ville købe dem, bære dem overalt og blive urolige, når de ikke er inden for rækkevidde.</p><blockquote>"The world is divided into three great super-states: Oceania, Eurasia, and Eastasia. They are perpetually at war with each other in shifting alliances. The war is not meant to be won—it is meant to be continuous." — George Orwell, *1984* (1949)</blockquote><p>Tre supermagter kæmper om kontrol over den digitale verden. Europa er det territorium, de deler mellem sig. Amerika tager dine data gennem platforme, du bruger dagligt. Kina fremstiller enhederne i din lomme. Rusland forgifter dit informationsmiljø. Alle tre behandler dig som en ressource, der skal udvindes, ikke som en borger, der skal beskyttes.</p><p>Europa kunne gøre modstand. Med 450 millioner mennesker og en økonomi på 17 billioner euro. I stedet bliver der scrollet videre.</p><p>Dette er den første af tre artikler, der undersøger Europas digitale situation gennem Orwells linse. Denne artikel kortlægger supermagterne. <a href="https://www.docupoint.eu/1984-2048-europe-under-siege/">Del 2</a> undersøger, hvordan Europa er målet. <a href="https://www.docupoint.eu/1984-2048-the-fourth-way/">Del 3</a> udforsker, om en fjerde vej eksisterer.</p><h2 id="de-tre-digitale-supermagter">De tre digitale supermagter</h2><h3 id="oceania-20-den-amerikanske-overv%C3%A5gningsmodel">Oceania 2.0: den amerikanske overvågningsmodel</h3><p>I 1984 er Oceanias ideologi "Ingsoc" (English Socialism), et regime, der lover frihed og leverer total kontrol. Partiets slogan, "Freedom is Slavery," indfanger modsætningen i hjertet af dets magt.</p><p>I 2026 har Amerikas ideologi et andet navn: <strong>overvågningskapitalisme</strong>.</p><p>Harvardprofessor <a href="https://news.harvard.edu/gazette/story/2019/03/harvard-professor-says-surveillance-capitalism-is-undermining-democracy/?ref=docupoint.eu">Shoshana Zuboff</a> definerer det som "the unilateral claiming of private human experience as free raw material for translation into behavioral data." Disse data pakkes derefter som forudsigelsesprodukter og sælges til annoncører, politiske kampagner og enhver, der vil betale for indsigt i, hvad du vil gøre næste gang.</p><p>Forretningsmodellen er enkel i sin udvinding: brugere genererer data, virksomheder indsamler dem, algoritmer behandler dem, og <a href="https://en.wikipedia.org/wiki/Surveillance_capitalism?ref=docupoint.eu">prædiktive modeller sælger dem til tredjeparter</a>. Google, Facebook, Amazon, Apple. De platforme, amerikanere bruger dagligt, kører på denne logik. Tjenesten er "gratis." Du er produktet.</p><h4 id="nsa-forbindelsen">NSA-forbindelsen</h4><p>Men overvågningskapitalisme er kun halvdelen af den amerikanske model. Den anden halvdel bærer et regeringsskilt.</p><p><a href="https://www.cloudwards.net/prism-snowden-and-government-surveillance/?ref=docupoint.eu">PRISM-programmet</a>, afsløret af Edward Snowden i 2013, viste, at NSA fik elektronisk kommunikation i realtid fra internetudbydere, herunder Microsoft, Yahoo, Google, Facebook, Skype, YouTube og Apple. Den føderale overvågningsdomstol (Foreign Intelligence Surveillance Court) fastslog, at PRISM står for <a href="https://www.eff.org/pages/upstream-prism?ref=docupoint.eu">91 % af de cirka 250 millioner internetkommunikationer</a>, der indsamles hvert år under Section 702.</p><p>Programmet stoppede ikke med Snowdens afsløringer. <a href="https://www.privacyjournal.net/edward-snowden-nsa-prism/?ref=docupoint.eu">Antallet af personer under PRISM-overvågning er vokset støt</a>: fra 89.138 overvågede mål i 2013 til 291.824 i 2024. Mål er lig med faktiske mennesker der er under komplet digital overvågning. I 2024, bare to dage efter Kongressen fornyede og udvidede Section 702, sendte FBI's vicedirektør en e-mail, der opfordrede agenter til at "bruge" overvågningsbeføjelsen.</p><p>Dette er Oceania-modellen opdateret til den digitale tidsalder: <strong>virksomhedsudvinding plus statslig adgang</strong>. Silicon Valley bygger infrastrukturen. NSA tapper den. <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">CLOUD Act</a> sikrer, at amerikansk lov rækker til alle data lagret af amerikanske virksomheder, uanset hvor i verden.</p><p>Partiet i 1984 overvågede gennem teleskærme. Amerika overvåger gennem platforme, du frivilligt downloadede, og hardware, du købte for dine egne penge. Oceanias slogan var "Freedom is Slavery." 2026-versionen: "Convenience is Surveillance."</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106085628.png" class="kg-image" alt="Convenience is Surveillance" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106085628.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106085628.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106085628.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Convenience is Surveillance: Den komfortable udvinding</span></figcaption></figure><h3 id="eurasia-20-den-russisk-kinesiske-akse">Eurasia 2.0: den russisk-kinesiske akse</h3><p>I 1984 strækker Eurasien sig over den eurasiske landmasse fra Portugal til Beringstrædet: en autoritær blok, hvor staten kontrollerer alt.</p><p>I 2026 er denne blok ved at dannes igen. Den 4. februar 2022, blot få uger, før Rusland invaderede Ukraine, annoncerede Xi Jinping og Vladimir Putin et partnerskab <a href="https://www.isdp.eu/75-years-of-china-russia-relations-indeed-a-no-limits-partnership/?ref=docupoint.eu">uden grænser</a> og uden "forbudte samarbejdsområder."</p><h4 id="partnerskabet-uden-gr%C3%A6nser">Partnerskabet "uden grænser"</h4><p>Det var ikke diplomatisk teater. I maj 2025 <a href="https://www.cfr.org/article/china-russia-ukraine-may-2025?ref=docupoint.eu">uddybede Kina og Rusland deres partnerskab yderligere</a> og underskrev aftaler inden for investering, handel, energi, rumfart og kultur. Præsidenterne Xi og Putin afviste offentligt den USA-ledede verdensorden og formulerede en ny vision med Beijing og Moskva i centrum.</p><p>Partnerskabet er asymmetrisk (Kina er den overordnede partner), men <a href="https://www.brookings.edu/articles/the-china-russia-relationship-and-threats-to-vital-us-interests/?ref=docupoint.eu">funktionelt integreret</a>:</p><ul><li><strong>Teknologioverførsel</strong>: Kinesiske forsvarsuniversiteter har markant øget forskningspartnerskaber med russiske institutioner siden 2019 og giver Moskva adgang til <a href="https://www.rferl.org/a/china-russia-xi-putin-military-university-drone-aircraft-engine/33533979.html?ref=docupoint.eu">strategiske teknologier afskåret af vestlige sanktioner</a>, især inden for luftfart og droneteknologi.</li><li><strong>Omgåelse af sanktioner</strong>: Kina forsyner Rusland med dual-use industrielle komponenter, herunder mikroelektronik, militær optik, dronemotorer og satellitteknologi. <a href="https://www.intereconomics.eu/contents/year/2025/number/2/article/china-russia-cooperation-economic-linkages-and-sanctions-evasion.html?ref=docupoint.eu">Næsten 90 % af russisk-kinesiske transaktioner</a> afregnes nu i yuan og rubler.</li><li><strong>Militær koordinering</strong>: Fælles øvelser, delte ubådsteknologier og samarbejde om AI og kvantecomputerforskning skaber en integreret forsvarsprofil.</li></ul><h4 id="kinas-overv%C3%A5gningsindustrielle-kompleks">Kinas overvågningsindustrielle kompleks</h4><p>Men partnerskabet rækker ud over militær hardware. Kina har opbygget, hvad Stanford-forskere kalder et <a href="https://stanfordrewired.com/post/china-surveillance/?ref=docupoint.eu">"overvågningsindustrielt kompleks"</a>. Og det er beregnet til eksport.</p><p>Gennem virksomheder som Huawei, Hikvision, Dahua og CloudWalk har Kina eksporteret sine "smart city"-overvågningsprodukter til <a href="https://www.brookings.edu/articles/exporting-the-surveillance-state-via-trade-in-ai/?ref=docupoint.eu">over 80 lande</a>. Mange er deltagere i Belt and Road Initiative. Teknologien omfatter ansigtsgenkendelse, videoanalyse, mobilsporing og datafusionsmuligheder.</p><ul><li>Huawei har bygget <a href="https://www.cfr.org/blog/china-huawei-5g?ref=docupoint.eu">cirka 70 % af Afrikas 4G-netværk</a></li><li><a href="https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/chinese-surveillance-ecosystem-and-the-global-spread-of-its-tools/?ref=docupoint.eu">266 kinesiske teknologiinitiativer</a> opererer på tværs af Afrika, fra datacentre til smart cities til overvågningsnetværk</li><li>Forskning på tværs af <a href="https://www.newsweek.com/china-ai-surveillance-technology-world-1403762?ref=docupoint.eu">90 lande</a> fandt, at kinesiske virksomheder eksporterer AI-overvågning til mindst 54</li></ul><p>I autokratier <a href="https://www.cambridge.org/core/journals/perspectives-on-politics/article/exporting-the-tools-of-dictatorship-the-politics-of-chinas-technology-transfers/D1A5B1D7C7A21FB5E601A553E6E8833F?ref=docupoint.eu">faciliterer Huawei-teknologi digital undertrykkelse</a>. CloudWalks ansigtsgenkendelsesdatabase i Zimbabwe bruges angiveligt til at overvåge regeringskritikere. Huawei-teknikere er blevet afsløret i politisk spionage i Uganda og Zambia.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106112353.png" class="kg-image" alt="The Surveillance Export Machine" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106112353.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106112353.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106112353.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Surveillance Export Machine: Kinas digitale infrastruktur spreder sig globalt</span></figcaption></figure><h4 id="ruslands-informationskrigsmaskineri">Ruslands informationskrigsmaskineri</h4><p>Rusland bidrager med en anden kapacitet til partnerskabet: informationskrig i stor skala. Mens Kina eksporterer overvågningshardware, eksporterer Rusland kaos.</p><p>Internet Research Agency, de desinformationskampagner, der er dokumenteret i Mueller-rapporten, operationerne rettet mod Brexit og europæiske valg: dette er ikke afvigelser. Det er <a href="https://www.lawfaremedia.org/article/russias-far-right-campaign-europe?ref=docupoint.eu">doktrin</a>. Gerasimov-doktrinen beskriver eksplicit, hvordan informationskrig kan opnå mål, som konventionel militær magt ikke kan.</p><p>I Orwells roman er Eurasien og Østasien sommetider allierede, sommetider fjender, men funktionelt identiske i deres totalitarisme. I 2026 repræsenterer Rusland og Kina forskellige varianter af den samme kontrolmodel: overvågningshardware fra Beijing, informationskrig fra Moskva, smeltet sammen til en enkelt autoritær teknologistak.</p><h3 id="hvorfor-kina-rusland-%C3%A9n-digital-fraktion">Hvorfor Kina + Rusland = én digital fraktion</h3><p>Orwell sammensmeltede Eurasien og Østasien til udskiftelige fjender, fordi deres systemer var funktionelt identiske. Trods kulturelle og historiske forskelle tjente begge det samme formål: total statskontrol over deres befolkninger.</p><p>Den samme logik gælder i dag. Trods spændinger og asymmetrier er Kina og Rusland konvergeret mod en fælles digital model:</p>
<!--kg-card-begin: html-->
<table style="max-width: 100%; width: 90%; table-layout: fixed; word-wrap: break-word;">
<thead>
<tr><th>Kapacitet</th><th>Kina</th><th>Rusland</th><th>Samlet effekt</th></tr>
</thead>
<tbody>
<tr><td><strong>Overvågningsteknologi</strong></td><td>Verdensledende inden for ansigtsgenkendelse, smart cities</td><td>Begrænset indenlandsk, importerer fra Kina</td><td>Global eksport af autoritær infrastruktur</td></tr>
<tr><td><strong>Informationskrig</strong></td><td>Statsmedier, censur</td><td>Trollfarme, desinformationskampagner</td><td>Koordinerede angreb på vestlige demokratier</td></tr>
<tr><td><strong>Internetmodel</strong></td><td>Great Firewall, total kontrol</td><td>RuNet, stigende isolation</td><td>Suverænt internet som skabelon for autokrater</td></tr>
<tr><td><strong>Teknologistandarder</strong></td><td>Alternativ til vestlige systemer</td><td>Adoption af kinesiske systemer</td><td>Parallelt digitalt økosystem uden for vestlig kontrol</td></tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>Erklæringen om "ingen grænser" fra februar 2022 var ikke begyndelsen på denne konvergens. Den var dens offentlige anerkendelse. Partnerskabet går forud for invasionen af Ukraine, vil overleve den og tjener begge regimers kerneinteresse: <strong>at demonstrere, at autoritarisme kan sameksistere med teknologisk modernitet</strong>.</p><p>Dette er Eurasien i 2026: ikke en enkelt monolitisk stat, men en <strong>koalition af autoritære digitale modeller</strong> forenet mod det liberale demokrati.</p><h2 id="den-evige-digitale-krig">Den evige digitale krig</h2><h3 id="vi-har-altid-v%C3%A6ret-i-cyberkrig-med">"Vi har altid været i cyberkrig med..."</h3><p>En af Orwells skarpeste indsigter: krigen mellem supermagterne er ikke beregnet til at blive vundet. Den er beregnet til at være permanent.</p><blockquote>"The war is waged by each ruling group against its own subjects, and the object of the war is not to make or prevent conquests of territory, but to keep the structure of society intact."</blockquote><p>Supermagterne skifter periodisk alliancer (Oceanien var altid i krig med Østasien; Oceanien var altid i krig med Eurasien), men selve krigen slutter aldrig. Dens formål er ikke sejr, men videreførelse.</p><h4 id="den-digitale-krig-har-ingen-v%C3%A5benstilstand">Den digitale krig har ingen våbenstilstand</h4><p>Cyberkonflikter følger den samme logik. Der er ingen fredstraktat at underskrive, intet territorium at udveksle, intet øjeblik hvor krigen slutter.</p><p><a href="https://www.cisa.gov/news-events/news/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure?ref=docupoint.eu">SolarWinds</a> var ikke et hack. Det var en besættelse. Russisk efterretningstjeneste levede inde i 18.000 organisationer i måneder, læste deres e-mails, overvågede deres beslutninger, kopierede deres hemmeligheder. Det amerikanske finansministerium, handelsministerium, ministeriet for indre sikkerhed: alle kompromitteret. Indtrængerne forsvandt, da de valgte det. Ikke da de blev opdaget.</p><p><a href="https://www.wired.com/story/china-microsoft-exchange-server-hack-victims/?ref=docupoint.eu">Microsoft Exchange</a> (2021): Kinesiske hackere udnyttede sårbarheder i hundredtusindvis af e-mailservere verden over. Din virksomhed kørte sandsynligvis Exchange. <a href="https://www.reuters.com/technology/colonial-pipeline-halts-all-pipeline-operations-after-cybersecurity-attack-2021-05-08/?ref=docupoint.eu">Colonial Pipeline</a> (2021): Russisk ransomware lukkede brændstofforsyningen til USA's østkyst. <a href="https://www.europarl.europa.eu/news/en/press-room/20221117IPR55010/european-parliament-detects-cyber-attack?ref=docupoint.eu">Europa-Parlamentet</a> (2022): Angrebet under en debat om russisk statsterrorisme. En besked leveret i realtid. <a href="https://www.reuters.com/world/europe/german-government-suffers-cyberattack-interior-ministry-says-2023-01-16/?ref=docupoint.eu">Den tyske regering</a> (2023, 2024, 2025): Gentagne indtrængen, tilskrevet russiske og kinesiske aktører, som Berlin kan dokumentere, men ikke stoppe.</p><p>Angrebene er kontinuerlige. Tilskrivningen er uklar. Reaktionerne er utilstrækkelige. Det er systemet.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106114430.png" class="kg-image" alt="The perpetual digital war" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106114430.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106114430.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106114430.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Den evige digitale krig: Angrebsvektorer der aldrig stopper</span></figcaption></figure><h3 id="den-virkelige-fjende-deres-egne-borgere">Den virkelige fjende: deres egne borgere</h3><p>Orwell forstod, at ekstern krig tjener intern kontrol. Partiet har brug for Eurasien og Østasien som fjender. Ikke for at besejre dem, men for at retfærdiggøre overvågningen af sin egen befolkning.</p><h4 id="amerikas-sikkerhedsskrue">Amerikas sikkerhedsskrue</h4><p>Efter 9/11 byggede USA et overvågningsapparat retfærdiggjort af krigen mod terror. Patriot Act. PRISM. Section 702. Hver krise udvidede statsmagten. Ingen indskrænkede den, da krisen var overstået.</p><p><a href="https://www.eff.org/pages/upstream-prism?ref=docupoint.eu">NSA indsamler 250 millioner internetkommunikationer årligt</a> under Section 702: kommunikation fra udlændinge, ja, men også amerikanere fanget i nettet. Begrundelsen er altid den samme: vi har brug for denne magt for at holde dig sikker mod ydre trusler.</p><h4 id="kinas-sociale-kontrol">Kinas sociale kontrol</h4><p>Kina gør forbindelsen eksplicit. <a href="https://en.wikipedia.org/wiki/Social_Credit_System?ref=docupoint.eu">Social credit-systemet</a>, de <a href="https://www.npr.org/2021/01/05/953515627/facial-recognition-and-beyond-journalist-ventures-inside-chinas-surveillance-sta?ref=docupoint.eu">200 millioner overvågningskameraer</a>, Great Firewall: alt retfærdiggjort som nødvendigt for stabilitet og sikkerhed. Ydre trusler (amerikansk inddæmning, taiwanesisk uafhængighed, uighurisk terrorisme) leverer begrundelsen for intern kontrol.</p><h4 id="ruslands-suver%C3%A6ne-internet">Ruslands suveræne internet</h4><p>Ruslands RuNet-projekt sigter mod at skabe et fuldt kontrollerbart indenlandsk internet, der kan afkobles fra det globale netværk. Begrundelsen: forsvar mod vestlige cyberangreb. Effekten: total kontrol over den information, der er tilgængelig for russiske borgere.</p><h4 id="et-f%C3%A6lles-m%C3%B8nster">Et fælles mønster</h4><p>Hver supermagt fortæller sine borgere: <em>Vi er nødt til at overvåge dig for at beskytte dig mod dem.</em> Den ydre fjende retfærdiggør den interne overvågning. Krigen, uanset om den er mod terrorisme, vestlig indflydelse eller østlig autoritarisme, er undskyldningen for teleskærmen.</p><p>I 1984 overvågede teleskærmene alle, altid. I 2026 gør smartphonen det samme. Og vi betaler for privilegiet.</p><p>Supermagterne har mere brug for hinanden som fjender, end de har brug for at besejre hinanden. Amerikansk overvågning kræver russiske hackere som begrundelse. Kinesisk kontrol kræver amerikansk inddæmning som undskyldning. Russisk undertrykkelse kræver NATO-udvidelse som rationale. Den evige krig holder alle tre systemer intakte.</p><p>Tre digitale supermagter, der hver overvåger deres borgere, der hver peger på de andre som begrundelse.</p><p>Men kig igen på Orwells kort. Læg mærke til, hvad der mangler.</p><p>I <a href="https://en.wikipedia.org/wiki/Political_geography_of_Nineteen_Eighty-Four?ref=docupoint.eu">Orwells geopolitiske vision</a> eksisterer Europa ikke. Storbritannien er opslugt af Oceanien. Det europæiske kontinent er slugt af Eurasien. Den civilisation, der gav verden Oplysningstiden, menneskerettighederne og demokratisk styring, er udslettet. Delt mellem rivaliserende imperier.</p><p>Det er den kurs, vi er på.</p><p>I <a href="https://www.docupoint.eu/1984-2048-europe-under-siege/">Del 2: Europa under belejring</a> undersøges det, hvordan supermagterne allerede arbejder på at absorbere Europa: gennem trollfarme og bankoverførsler, gennem kompromitterede politikere og erobrede platforme. Belejringen er ikke på vej. Den er begyndt.</p><p>450 millioner mennesker og 17 billioner euro i BNP, et marked stort nok til at sætte globale standarder, alt sammen afhængigt af amerikanske platforme, kinesisk hardware og sårbart over for russisk informationskrig.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106115710.png" class="kg-image" alt="Europe: The Disputed Territory" loading="lazy" width="1415" height="762" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106115710.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106115710.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106115710.png 1415w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Europa: Det omstridte territorium, fanget mellem digitale imperier</span></figcaption></figure><p>Klokken slår tretten.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Microsofts danske datacentre og Copilot-overraskelsen: Hvad europæiske virksomheder skal vide]]></title>
                    <description><![CDATA[Microsoft aktiverede Anthropics Claude i Copilot – uden for EU Data Boundary. En enkelt admin-knap kan sende data til amerikansk infrastruktur. Her er hvad europæiske virksomheder skal tjekke nu.]]></description>
                    <link>https://www.docupoint.eu/da/microsofts-danske-datacentre-copilot-overraskelsen/</link>
                    <guid isPermaLink="false">69b08c3c14da570001b326e0</guid>

                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[GDPR]]></category>
                        <category><![CDATA[microsoft]]></category>
                        <category><![CDATA[copilot]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Tue, 10 Mar 2026 22:32:13 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/photo-1451187580459-43490279c0fa-1.jpeg" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/photo-1451187580459-43490279c0fa-1.jpeg" alt="Microsofts danske datacentre og Copilot-overraskelsen: Hvad europæiske virksomheder skal vide"/> <p>Microsoft bygger stort i Danmark. I december 2020 <a href="https://news.microsoft.com/source/emea/features/microsoft-announces-plans-to-establish-a-new-datacenter-region-in-denmark-to-accelerate-the-countrys-green-digital-transformation/?ref=docupoint.eu" rel="noopener">annoncerede selskabet sin første danske datacenterregion</a> – "Denmark East" – med faciliteter i Hovedstadsregionen og på Sjælland. Efter fem års byggeri er regionen planlagt til lancering i første halvår af 2026. Så, i december 2025, annoncerede Microsoft <a href="https://news.microsoft.com/source/emea/features/accelerating-europes-digital-future-microsoft-announces-plans-for-a-new-datacenter-region-in-west-denmark/?ref=docupoint.eu" rel="noopener">en anden region: "West Denmark"</a> med tre nye faciliteter i Varde og Esbjerg kommuner, beskrevet som selskabets største enkeltinvestering i dets 36-årige danske historie. Alene mellem 2023 og 2027 investerer Microsoft 3 milliarder dollars i datacenterkapacitet på dansk grund – og West Denmark-udvidelsen vil skubbe det tal endnu højere.</p><p>For europæiske IT-ledere ser narrativet ud som en gevinst. Microsoft-tjenester der kører på dansk grund. Lokale arbejdspladser. CO2-fri energi. Et skridt tættere på at holde europæiske data i Europa.</p><p>Så, den 7. januar 2026, skete der noget andet – og de fleste organisationer gik fuldstændig glip af det.</p><h3 id="den-stille-%C3%A6ndring-i-copilot">Den stille ændring i Copilot</h3><p>På den dato aktiverede Microsoft Anthropics Claude AI-modeller som underdatabehandler på tværs af Microsoft 365 Copilot. For kommercielle tenants uden for EU var knappen sat til <strong>TIL som standard</strong>. Ingen handling krævet. Ingen notifikation til slutbrugere. Bare en ny AI-model der behandler deres data ved siden af OpenAIs GPT.</p><p>De funktioner der drives af Anthropics Claude inkluderer Microsoft 365 Copilot på web, desktop og mobil, Researcher-agenten, Copilot Studio, Power Platform, Agent Mode i Excel samt Word-, Excel- og PowerPoint-agenterne. Det er ikke marginale funktioner – det er kerneprodukter som millioner af vidensarbejdere bruger dagligt.</p><p>Her er den kritiske detalje: <strong>Anthropic-modeller er eksplicit udelukket fra Microsofts EU Data Boundary.</strong> <a href="https://learn.microsoft.com/en-us/copilot/microsoft-365/connect-to-ai-subprocessor?ref=docupoint.eu" rel="noopener">Microsofts egen dokumentation</a> siger det ligeud: <em>"Anthropic models deployed in Microsoft offerings are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments."</em></p><p>For EU/EFTA- og UK-tenants satte Microsoft knappen til FRA som standard. En ansvarlig beslutning. Men knappen eksisterer. Og der skal kun en enkelt Global Administrator til for at slå den til. Måske under pres for at give brugerne adgang til de nyeste Copilot-funktioner. Måske uden fuldt ud at forstå konsekvenserne for dataopbevaring.</p><h3 id="hvad-der-sker-n%C3%A5r-indstillingen-bliver-aktiveret">Hvad der sker når indstillingen bliver aktiveret</h3><p>Når en M365-administrator aktiverer Anthropic som Microsoft-underdatabehandler, fravælger organisationen eksplicit <a href="https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-learn?ref=docupoint.eu" rel="noopener">EU Data Boundary</a>-beskyttelsen for data der behandles af disse modeller. Data behøver ikke længere at forblive inden for EU/EØS-infrastruktur. Anthropic behandler data på tværs af amerikansk, europæisk, asiatisk og australsk infrastruktur, med lagring i amerikanske datacentre.</p><p>Det er ikke en fejl. Microsoft har været transparent omkring det – informationen er tilgængelig i admin-centeret og i Microsofts dokumentation. Men "transparent" og "bredt forstået" er ikke det samme. Hvor mange IT-administratorer i danske SMV'er har gennemgået Microsofts underdatabehandlerdokumentation? Hvor mange DPO'er er blevet konsulteret før indstillingen blev ændret?</p><p>Risikoen forstærkes af, at brugerne ikke kan se hvilken AI-model der behandler deres forespørgsel i de fleste Copilot-oplevelser. En medarbejder der bruger Copilot i Word ved ikke – og kan ikke nemt afgøre – om deres dokumentindhold behandles af OpenAI (inden for EU Data Boundary) eller af Anthropic (uden for). Administratoren traf en enkelt beslutning i et indstillingspanel. Brugeren er uvidende.</p><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-emoji">⚠️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Denne knap kan ikke rulles tilbage.</strong></b> At aktivere Anthropic og senere slå det fra stopper <i><em class="italic" style="white-space: pre-wrap;">fremtidig</em></i> data fra at forlade EU – men hver eneste forespørgsel og dokument der allerede er behandlet af Anthropic, er sendt til amerikansk infrastruktur (angiveligt AWS). De data kan ikke trækkes tilbage, gøres ugjort eller slettes gennem Microsofts standard compliance-værktøjer. GDPR Artikel 17 (retten til sletning) mod en amerikansk-hostet underdatabehandler af en underdatabehandler har ingen etableret præcedens. En enkelt administratorbeslutning – der ikke kræver DPO-godkendelse og ingen konsekvensanalyse – kan skabe en irreversibel compliance-hændelse. Fra-knappen er ikke en fortryd-knap.</div></div><h3 id="selv-uden-anthropic-datacenter-illusionen">Selv uden Anthropic: Datacenter-illusionen</h3><p>Selv med Anthropic-knappen sikkert i FRA-positionen er der et dybere strukturelt problem som Microsofts danske datacentre ikke løser.</p><p>Microsoft er et amerikansk selskab. Dets danske datterselskaber – de enheder der vil drive faciliteterne i Esbjerg, Varde og Hovedstadsregionen – er kontrolleret af et amerikansk moderselskab. To amerikanske love gør forskellen mellem <em>hvor dataene befinder sig</em> og <em>hvor selskabet er registreret</em> kritisk vigtig:</p><p><a href="https://www.law.cornell.edu/uscode/text/50/1881a?ref=docupoint.eu" rel="noopener"><strong>FISA Section 702</strong></a> giver amerikanske efterretningstjenester ret til at pålægge amerikanske selskaber at udlevere adgang til kommunikationsdata fra ikke-amerikanske personer. Den gælder selskabet, ikke serveren. Et Microsoft-datacenter i Danmark er lige så tilgængeligt under FISA 702 som et i Virginia.</p><p><a href="https://www.justice.gov/criminal/cloud-act-resources?ref=docupoint.eu" rel="noopener"><strong>CLOUD Act</strong></a> (2018) gør det eksplicit: Amerikanske myndigheder kan pålægge amerikanske selskaber at udlevere data der er lagret på servere uden for USA. Dataene behøver ikke være i USA. Det skal selskabet.</p><p><a href="https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en?ref=docupoint.eu" rel="noopener">EU-US Data Privacy Framework</a> (DPF), vedtaget i 2023, udgør det nuværende retsgrundlag for denne behandling. Men dets to forgængere – Safe Harbor (ugyldiggjort 2015, <a href="https://curia.europa.eu/juris/liste.jsf?num=C-362%2F14&ref=docupoint.eu" rel="noopener"><em>Schrems I</em></a>) og Privacy Shield (ugyldiggjort 2020, <a href="https://curia.europa.eu/juris/documents.jsf?num=C-311%2F18&ref=docupoint.eu" rel="noopener"><em>Schrems II</em></a>) – blev underkendt af EU-Domstolen af præcis samme grundlæggende årsag: Amerikansk overvågningslovgivning giver utilstrækkelig beskyttelse for europæiske borgere. DPF hviler på en eksekutiv ordre der kan ændres af enhver fremtidig amerikansk præsident. En juridisk udfordring – almindeligvis omtalt som <a href="https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-round-cjeu?ref=docupoint.eu" rel="noopener"><em>Schrems III</em></a> – er bredt forventet.</p><p>Intet af dette gør Microsoft ulovligt eller ubrugeligt. DPF er i kraft. Microsofts EU Data Boundary er en reel teknisk indsats. For de fleste europæiske organisationer er Microsoft 365 det praktiske og lovlige valg.</p><p>Men <strong>EU-datacenter er ikke lig med EU-datasuverænitet</strong>. Og din governance bør afspejle det.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal   kg-cta-link-accent " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p><span style="white-space: pre-wrap;">Strator har brugt 25 år på at hjælpe europæiske organisationer med at håndtere, klassificere og styre deres dokumenter – fra SharePoint-migrationer til GDPR-compliance. Hvis du ikke er sikker på, hvordan disse jurisdiktionsmæssige problemer påvirker dit specifikke setup, kan vi hjælpe med at finde ud af det.</span></p>
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Tal med Strator
                        </a>
                        
                    </div>
                
            </div>
        </div><h3 id="den-multi-model-fremtid">Den multi-model fremtid</h3><p>Det der gør Anthropic-integrationen særligt vigtig, er at den signalerer en retning, ikke bare en hændelse. Microsofts Business and Industry Copilot-præsident Charles Lamanna formulerede det som at give kunder "fleksibiliteten til også at bruge Anthropic-modeller." Copilot er ved at blive en multi-model-orkestrator – der dirigerer forskellige opgaver til forskellige AI-udbydere baseret på kapabilitet, ikke geografi.</p><p>I dag er det Anthropic. I morgen kan det være en anden udbyder. Mønsteret er klart: den AI-tjeneste som brugere interagerer med, er ikke længere en enkelt model fra en enkelt udbyder med et enkelt sæt dataopbevaringsforpligtelser. Det er en platform der dirigerer opgaver bag kulisserne, og hver rute kan have forskellige jurisdiktionsmæssige karakteristika.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">"Vi bruger Microsoft Copilot" er ikke længere et svar på, hvor data behandles.</strong></b> Copilot er ikke ét produkt med én datagrænse. Det er en platform der sender forespørgsler og dokumenter til forskellige AI-udbydere – med forskellige dataopbevaringsforpligtelser – afhængigt af funktionen, opgaven og en enkelt administratorindstilling i din tenant. At data forbliver under Microsofts kontrol er ikke længere garanteret af, at man bruger Microsofts produkt. Hvis organisationens compliance-position antager at Copilot = Microsoft = EU Data Boundary, er den antagelse allerede forældet.</div></div><h3 id="hvor-g%C3%A5r-data-egentlig-hen-ai-leverand%C3%B8roversigt">Hvor går data egentlig hen? AI-leverandøroversigt</h3><p>For at forstå det reelle billede er det vigtigt at vide, hvor hver større AI-udbyder behandler data – og helt afgørende, hvor den udbyder er registreret.</p><hr><p><em>Grøn = EU-baseret udbyder. Gul = EU-opbevaring tilgængelig eller betinget. Rød = ingen EU-dataopbevaring.</em></p><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Microsoft 365 Copilot (OpenAI-drevne funktioner)</strong></b><br>HQ: USA — EU Dataopbevaring: Ja (EU Data Boundary)Forespørgsler og svar behandles inden for EU for kvalificerede tenants. Dækker standard Copilot i Word, Excel, PowerPoint, Outlook, Teams.</div></div><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Microsoft 365 Copilot (Anthropic-drevne funktioner)</strong></b><br>HQ: USA — EU Dataopbevaring: NejResearcher, Copilot Studio-agenter, Agent Mode i Excel, Word/Excel/PowerPoint-agenter. <b><strong style="white-space: pre-wrap;">Eksplicit udelukket fra EU Data Boundary.</strong></b> FRA som standard for EU-tenants.</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">OpenAI (direkte)</strong></b><br>HQ: USA — EU Dataopbevaring: Kun EnterpriseEU-opbevaring via <code spellcheck="false" style="white-space: pre-wrap;">eu.api.openai.com</code> for enterprise API-kunder. ChatGPT Enterprise/Education kan konfigureres til EU. Forbrugerplaner (Plus, Pro, Team): ingen EU-opbevaring.</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Azure OpenAI</strong></b><br>HQ: USA — EU Dataopbevaring: Ja (Data Zone EUR)Data Zone Standard (EUR) = kun EU-behandling. Regional deployment (f.eks. Sweden Central) = enkelt region. Global deployment = kan dirigere hvorsom helst (ikke egnet til EU-følsomme data).</div></div><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Anthropic Claude (direkte)</strong></b><br>HQ: USA — EU Dataopbevaring: NejIngen EU-dataopbevaring for nogen direkte tjeneste (claude.ai, Cowork, Claude Desktop, API). EU-behandling kun tilgængelig via Amazon Bedrock (eu-west-1, eu-central-1) eller Google Vertex AI (europe-west-regioner).</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Google Gemini / Vertex AI</strong></b><br>HQ: USA — EU Dataopbevaring: Kun VertexVertex AI understøtter EU-region-deployment. Gemini forbrugerprodukter: ingen EU-opbevaringsgaranti.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Mistral AI</strong></b><br>HQ: Frankrig — EU Dataopbevaring: JaEU-hovedkvarter. API og Le Chat behandles på EU-infrastruktur. Helt uden for amerikansk jurisdiktion.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Aleph Alpha</strong></b><br>HQ: Tyskland — EU Dataopbevaring: JaEU-hovedkvarter. Luminous-modeller med kun-EU-behandling. Helt uden for amerikansk jurisdiktion.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Selvhostet (Llama, Mistral open-weights osv.)</strong></b><br>EU Dataopbevaring: Afhænger af hostingplaceringEU-cloududbydere (Hetzner, OVH, Scaleway) = stærkest suverænitet. AWS/Azure/GCP EU-regioner = amerikansk moderselskab gælder stadig.</div></div><p>Tabellen afslører et mønster: EU-dataopbevaring fra et amerikansk selskab er teknisk reel, men juridisk skrøbelig. EU-dataopbevaring fra et EU-selskab er strukturelt solid. Og selvhostede modeller giver mest kontrol – men kræver den største investering.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers  kg-cta-link-accent " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p><span style="white-space: pre-wrap;">Med 25 års erfaring i dokumenthåndtering og datastyring på tværs af Microsoft 365-miljøer hjælper Strator organisationer med at forstå, hvilke leverandørmuligheder der matcher deres risikoprofil – og bygge den klassificering der håndhæver det.</span></p>
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Tal med os
                        </a>
                        
                    </div>
                
            </div>
        </div><h3 id="hvad-du-b%C3%B8r-g%C3%B8re-nu">Hvad du bør gøre nu</h3><p><strong>1. Tjek knappen.</strong> Log ind på Microsoft 365 admin center → Copilot → Settings → Data access → AI providers operating as Microsoft subprocessors. Verificér at Anthropic er deaktiveret, hvis organisationen kræver EU Data Boundary-overholdelse. Kun en Global Administrator kan ændre denne indstilling.</p><p><strong>2. Dokumentér beslutningen.</strong> Uanset om Anthropic holdes fra eller slås til, dokumentér begrundelsen. DPO'en bør være involveret. Hvis det aktiveres, registrér at organisationen bevidst accepterer databehandling uden for EU Data Boundary og opdatér ROPA i overensstemmelse hermed.</p><p><strong>3. Klassificér data.</strong> Ikke alle data bærer den samme risiko. Offentligt markedsføringsindhold behandlet af Anthropic uden for EU er en helt anden situation end interne HR-dokumenter eller klientkontraktdetaljer. En ordentlig dataklassificering – hvad der må behandles af AI, under hvilke betingelser og gennem hvilke udbydere – er fundamentet for governance i en multi-model-verden.</p><p><strong>4. Overvåg underdatabehandlerlisten.</strong> Microsoft kan tilføje nye AI-underdatabehandlere. Gennemgå tenantens underdatabehandlerindstillinger kvartalsvist. Sæt en kalenderpåmindelse. Antag ikke at dagens konfiguration er permanent.</p><p><strong>5. Hav en beredskabsplan.</strong> Hvis EU-US Data Privacy Framework bliver ugyldiggjort, vil enhver europæisk organisation der bruger Microsoft, OpenAI, Google eller enhver anden amerikansk cloududbyder, være nødt til at revurdere. Vid hvilke workloads der kan flyttes til EU-baserede udbydere. Begynd at evaluere alternativer nu – ikke når EU-Domstolens afgørelse falder.</p><h3 id="den-ubehagelige-sandhed">Den ubehagelige sandhed</h3><p>At Microsoft investerer milliarder i dansk infrastruktur er godt for Danmark. Flere lokale datacentre betyder lavere latenstid, lokale arbejdspladser og bedre disaster recovery. Ingen foreslår at europæiske organisationer skal holde op med at bruge Microsoft.</p><p>Men europæiske IT-ledere skal forstå, hvad de faktisk køber. Et datacenter i Danmark giver nærhed. Det giver ydeevne. Det giver et flag på et kort der ser betryggende ud i bestyrelseslokalet.</p><p>Det giver ikke suverænitet. Suverænitet kræver at dataene er uden for den juridiske rækkevidde af en fremmed regering. Så længe selskabet der driver datacenteret er registreret i USA, er det ikke tilfældet.</p><p>Organisationer der forstår dette i dag, klassificerer deres data, konfigurerer deres admin-knapper bevidst og bygger beredskabsplaner. De kommer til at stå langt bedre, når det næste regulatoriske skift rammer.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal    kg-cta-centered" data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p><b><strong style="white-space: pre-wrap;">Ikke sikker på hvor du skal starte?</strong></b><span style="white-space: pre-wrap;"> Dataklassificering til AI-adgang er komplekst, men det behøver ikke være overvældende. Strator hjælper europæiske organisationer med at klassificere deres data, konfigurere deres Microsoft 365-miljøer og bygge governance der rent faktisk virker.</span></p>
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Kontakt Strator
                        </a>
                        
                    </div>
                
            </div>
        </div>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[How to Monitor Multiple SharePoint Lists Across Sites with Just Two Flows]]></title>
                    <description><![CDATA[How to use SharePoint webhooks to monitor multiple lists across multiple sites with just two flows instead of dozens. Complete beginner-friendly implementation guide.]]></description>
                    <link>https://www.docupoint.eu/blog/use-one-flow-to-trigger-multiple-sharepoint-lists-from-multiple-sites/</link>
                    <guid isPermaLink="false">69a5475df2a7c50001c7f763</guid>

                        <category><![CDATA[Power Automate]]></category>
                        <category><![CDATA[Logic Apps]]></category>
                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[Webhooks]]></category>
                        <category><![CDATA[REST API]]></category>
                        <category><![CDATA[Automation]]></category>
                        <category><![CDATA[Azure]]></category>
                        <category><![CDATA[Field Notes]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 02 Mar 2026 09:20:28 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Pasted-image-20260104163013-1.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Pasted-image-20260104163013-1.png" alt="How to Monitor Multiple SharePoint Lists Across Sites with Just Two Flows"/> <h2 id="overview">Overview</h2><p><strong>What you'll learn</strong>: How to monitor multiple SharePoint lists across multiple sites using just two flows instead of dozens.</p><p><strong>Time required</strong>: 60-90 minutes</p><p><strong>Prerequisites</strong>:</p><ul><li>Power Automate Premium license OR Azure Logic Apps access</li><li>SharePoint site collection administrator permissions</li><li>A SharePoint site for storing configuration lists</li></ul><p><strong>What you'll build</strong>:</p><ul><li>Two SharePoint lists for configuration</li><li>One flow to manage webhook subscriptions</li><li>One flow to handle change notifications</li></ul><hr><h2 id="the-problem">The Problem</h2><p>If you need to monitor 50 SharePoint lists for changes, the obvious approach requires 50 separate flows. This creates a management nightmare with 50 flows to maintain and update.</p><p><strong>The solution</strong>: Use SharePoint webhooks. Instead of 50 flows, you need exactly two:</p><ol><li><strong>Subscription Flow</strong> – Creates and renews webhook subscriptions (runs monthly)</li><li><strong>Handler Flow</strong> – Receives notifications and processes changes (triggered automatically)</li></ol><hr><h2 id="architecture-overview">Architecture Overview</h2><figure class="kg-card kg-image-card kg-width-wide"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Architecture-Overview-1.jpg" class="kg-image" alt="Architecture Overview" loading="lazy" width="1376" height="768" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/03/Architecture-Overview-1.jpg 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/03/Architecture-Overview-1.jpg 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/03/Architecture-Overview-1.jpg 1376w" sizes="(min-width: 1200px) 1200px"></figure><p>The Subscription Flow runs once per month. It loops through all your sites, finds lists matching your criteria, and creates webhook subscriptions pointing to the Handler Flow.</p><p>When something changes on any monitored list, SharePoint sends a notification to the Handler Flow. The Handler Flow then queries the list to find what changed and executes your business logic.</p><hr><h2 id="licensing-note">Licensing Note</h2><p>This solution requires <strong>Power Automate Premium</strong> because the Handler Flow uses the "When a HTTP request is received" trigger (a premium connector).</p><p><strong>Alternative</strong>: Use <strong>Azure Logic Apps</strong> with consumption-based pricing. This is often more cost-effective for low-volume scenarios and doesn't require a premium license.</p><p>The instructions below work for both Power Automate and Logic Apps.</p><hr><h2 id="part-1-create-the-configuration-lists">Part 1: Create the Configuration Lists</h2><p>Before building the flows, you need two SharePoint lists to store configuration data.</p><h3 id="step-11-create-the-sites-list">Step 1.1: Create the Sites List</h3><p>This list stores the SharePoint sites you want to monitor.</p><h4 id="step-111-navigate-to-your-management-site">Step 1.1.1: Navigate to Your Management Site</h4><ol><li>Open your browser and go to the SharePoint site where you want to store the configuration</li><li>This could be any site, for example: <code>https://yourtenant.sharepoint.com/sites/management</code></li></ol><h4 id="step-112-create-a-new-list">Step 1.1.2: Create a New List</h4><ol><li>Click <strong>+ New</strong> in the top left</li><li>Click <strong>List</strong></li><li>Select <strong>Blank list</strong></li><li>Enter the name: <code>Sites</code></li><li>Click <strong>Create</strong></li></ol><h4 id="step-113-add-the-url-column">Step 1.1.3: Add the URL Column</h4><p>The list already has a Title column. You need to add one more column.</p><ol><li>Click <strong>+ Add column</strong></li><li>Select <strong>Single line of text</strong></li><li>Enter the name: <code>URL</code></li><li>Click <strong>Save</strong></li></ol><h4 id="step-114-add-your-sites">Step 1.1.4: Add Your Sites</h4><p>Add one row for each site you want to monitor. For example, your first entry might have the Title <code>Sales Site</code> with the URL <code>https://yourtenant.sharepoint.com/sites/sales</code>. Add additional rows for each site, such as <code>HR Site</code> pointing to <code>https://yourtenant.sharepoint.com/sites/hr</code> and <code>Projects Site</code> pointing to <code>https://yourtenant.sharepoint.com/sites/projects</code>.</p><hr><h3 id="step-12-create-the-timestamps-list">Step 1.2: Create the Timestamps List</h3><p>This list tracks when each monitored list was last processed.</p><h4 id="step-121-create-the-list">Step 1.2.1: Create the List</h4><ol><li>Click <strong>+ New</strong> in the top left</li><li>Click <strong>List</strong></li><li>Select <strong>Blank list</strong></li><li>Enter the name: <code>Timestamps</code></li><li>Click <strong>Create</strong></li></ol><h4 id="step-122-add-the-required-columns">Step 1.2.2: Add the Required Columns</h4><p>Add three columns:</p><p><strong>Column 1: listGUID</strong></p><ol><li>Click <strong>+ Add column</strong></li><li>Select <strong>Single line of text</strong></li><li>Enter the name: <code>listGUID</code></li><li>Click <strong>Save</strong></li></ol><p><strong>Column 2: SiteURL</strong></p><ol><li>Click <strong>+ Add column</strong></li><li>Select <strong>Single line of text</strong></li><li>Enter the name: <code>SiteURL</code></li><li>Click <strong>Save</strong></li></ol><p><strong>Column 3: LastModificationDateTime</strong></p><ol><li>Click <strong>+ Add column</strong></li><li>Select <strong>Date and time</strong></li><li>Enter the name: <code>LastModificationDateTime</code></li><li>Click <strong>Save</strong></li></ol><p>You'll populate this list later when the Subscription Flow runs.</p><hr><h2 id="part-2-create-the-handler-flow">Part 2: Create the Handler Flow</h2><p>You must create the Handler Flow first because you need its URL for the Subscription Flow.</p><h3 id="step-21-create-a-new-flow">Step 2.1: Create a New Flow</h3><h4 id="step-211-open-power-automate">Step 2.1.1: Open Power Automate</h4><ol><li>Go to <a href="https://make.powerautomate.com/?ref=docupoint.eu">https://make.powerautomate.com</a></li><li>Sign in with your Microsoft 365 account</li></ol><h4 id="step-212-create-the-flow">Step 2.1.2: Create the Flow</h4><ol><li>Click <strong>+ Create</strong> in the left menu</li><li>Click <strong>Instant cloud flow</strong></li><li>Enter the flow name: <code>Webhook Handler</code></li><li>Scroll down and select <strong>When a HTTP request is received</strong></li><li>Click <strong>Create</strong></li></ol><hr><h3 id="step-22-configure-the-http-trigger">Step 2.2: Configure the HTTP Trigger</h3><h4 id="step-221-get-the-http-url">Step 2.2.1: Get the HTTP URL</h4><p>After creating the flow, you'll see the trigger action open.</p><ol><li>Leave <strong>Request Body JSON Schema</strong> empty for now</li><li>Click <strong>Save</strong> in the top right</li><li>After saving, the <strong>HTTP POST URL</strong> field will show a long URL</li><li>Click the <strong>copy icon</strong> next to the URL</li><li><strong>Save this URL somewhere</strong> – you'll need it for the Subscription Flow</li></ol><p>The URL looks like this:</p><pre><code>https://prod-XX.westeurope.logic.azure.com:443/workflows/abc123.../triggers/manual/paths/invoke?api-version=...</code></pre><hr><h3 id="step-23-add-the-response-action">Step 2.3: Add the Response Action</h3><p>SharePoint expects a response within 5 seconds. You must respond immediately.</p><h4 id="step-231-add-the-response">Step 2.3.1: Add the Response</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Response</code></li><li>Select <strong>Response</strong> (under "Request")</li><li>Set <strong>Status Code</strong> to: <code>200</code></li><li>Leave <strong>Body</strong> empty</li></ol><hr><h3 id="step-24-add-variables">Step 2.4: Add Variables</h3><p>You need to initialize variables to store data during processing.</p><h4 id="step-241-add-variable-for-headers">Step 2.4.1: Add Variable for Headers</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>header_nometa</code></li><li><strong>Type</strong>: Select <strong>Object</strong></li><li><strong>Value</strong>: </li></ol><h4 id="step-242-add-variable-for-list-guid">Step 2.4.2: Add Variable for List GUID</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>ListGUID</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Leave empty</li></ol><h4 id="step-243-add-variable-for-site-url">Step 2.4.3: Add Variable for Site URL</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>listSiteURL</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Leave empty</li></ol><h4 id="step-244-add-variable-for-timestamp">Step 2.4.4: Add Variable for Timestamp</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>lastModifiedTime</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Leave empty</li></ol><hr><h3 id="step-25-handle-validation-requests">Step 2.5: Handle Validation Requests</h3><p>When creating a subscription, SharePoint sends a validation request first. You must detect and handle this.</p><h4 id="step-251-add-a-condition">Step 2.5.1: Add a Condition</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Condition</code></li><li>Select <strong>Condition</strong> (under "Control")</li></ol><h4 id="step-252-configure-the-condition">Step 2.5.2: Configure the Condition</h4><p>In the condition, you'll check if the Content-Length header is 0 (meaning it's a validation request).</p><ol><li>In the first field (left side), click in the box</li><li>Click <strong>Expression</strong> tab</li><li>Enter: <code>int(triggerOutputs()?['headers']?['Content-Length'])</code></li><li>Click <strong>OK</strong></li><li>In the middle dropdown, select <strong>is equal to</strong></li><li>In the right field, enter: <code>0</code></li></ol><hr><h3 id="step-26-configure-the-if-yes-branch-validation">Step 2.6: Configure the "If Yes" Branch (Validation)</h3><p>When Content-Length is 0, it's a validation request. You must return the validation token.</p><h4 id="step-261-add-response-in-if-yes">Step 2.6.1: Add Response in "If Yes"</h4><ol><li>Click inside the <strong>If yes</strong> branch</li><li>Click <strong>Add an action</strong></li><li>Search for <code>Response</code></li><li>Select <strong>Response</strong></li><li>Configure:</li><li><strong>Status Code</strong>: <code>200</code></li><li>Click <strong>Show advanced options</strong></li><li>Under <strong>Headers</strong>, click <strong>+ Add new item</strong></li><li><strong>Key</strong>: <code>Content-Type</code></li><li><strong>Value</strong>: <code>text/plain</code></li><li><strong>Body</strong>: Click in the box, then click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><h4 id="step-262-add-terminate-action">Step 2.6.2: Add Terminate Action</h4><ol><li>Click <strong>Add an action</strong> (still in "If yes" branch)</li><li>Search for <code>Terminate</code></li><li>Select <strong>Terminate</strong> (under "Control")</li><li>Set <strong>Status</strong> to: <strong>Succeeded</strong></li></ol><hr><h3 id="step-27-configure-the-if-no-branch-change-notification">Step 2.7: Configure the "If No" Branch (Change Notification)</h3><p>When Content-Length is not 0, it's an actual change notification.</p><h4 id="step-271-set-the-listguid-variable">Step 2.7.1: Set the ListGUID Variable</h4><ol><li>Click inside the <strong>If no</strong> branch</li><li>Click <strong>Add an action</strong></li><li>Search for <code>Set variable</code></li><li>Select <strong>Set variable</strong></li><li>Configure:</li><li><strong>Name</strong>: Select <code>ListGUID</code></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><h4 id="step-272-set-the-listsiteurl-variable">Step 2.7.2: Set the listSiteURL Variable</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Set variable</code></li><li>Select <strong>Set variable</strong></li><li>Configure:</li><li><strong>Name</strong>: Select <code>listSiteURL</code></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li><li><strong>Important</strong>: Replace <code>yourtenant</code> with your actual tenant name</li></ol><h4 id="step-273-get-the-last-processed-timestamp">Step 2.7.3: Get the Last Processed Timestamp</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Enter your management site URL (e.g., <code>https://yourtenant.sharepoint.com/sites/management</code>)</li><li><strong>Method</strong>: Select <strong>GET</strong></li><li><strong>Uri</strong>: </li><li><strong>Headers</strong>: Click <strong>+ Add new item</strong></li><li><strong>Key</strong>: <code>Accept</code></li><li><strong>Value</strong>: <code>application/json; odata=nometadata</code></li></ol><h4 id="step-274-set-the-lastmodifiedtime-variable">Step 2.7.4: Set the lastModifiedTime Variable</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Set variable</code></li><li>Select <strong>Set variable</strong></li><li>Configure:</li><li><strong>Name</strong>: Select <code>lastModifiedTime</code></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><h4 id="step-275-update-the-timestamp">Step 2.7.5: Update the Timestamp</h4><p>Update the timestamp before processing to prevent duplicate processing.</p><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Your management site URL</li><li><strong>Method</strong>: Select <strong>POST</strong></li><li><strong>Uri</strong>: Click <strong>Expression</strong> and enter:</li><li><strong>Headers</strong>: Click <strong>Switch to text mode</strong> (if available) or add these items:</li><li><code>Accept</code>: <code>application/json;odata=nometadata</code></li><li><code>Content-Type</code>: <code>application/json;odata=nometadata</code></li><li><code>IF-MATCH</code>: <code>*</code></li><li><code>X-HTTP-Method</code>: <code>MERGE</code></li><li><strong>Body</strong>:</li></ol><h4 id="step-276-get-modified-items">Step 2.7.6: Get Modified Items</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Get items</code></li><li>Select <strong>Get items</strong> (SharePoint)</li><li>Configure:</li><li><strong>Site Address</strong>: Click in the box, then select <strong>Enter custom value</strong>, then select <code>listSiteURL</code> from Dynamic content</li><li><strong>List Name</strong>: Click in the box, then select <strong>Enter custom value</strong>, then select <code>ListGUID</code> from Dynamic content</li><li>Click <strong>Show advanced options</strong></li><li><strong>Filter Query</strong>: </li></ol><h4 id="step-277-process-each-modified-item">Step 2.7.7: Process Each Modified Item</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Apply to each</code></li><li>Select <strong>Apply to each</strong> (under "Control")</li><li>In <strong>Select an output from previous steps</strong>, select <code>value</code> from the "Get items" action</li></ol><p>Inside this loop, add your business logic (send emails, update records, etc.).</p><hr><h3 id="step-28-save-the-flow">Step 2.8: Save the Flow</h3><ol><li>Click <strong>Save</strong> in the top right corner</li><li>Verify the flow saves without errors</li></ol><hr><h2 id="part-3-create-the-subscription-flow">Part 3: Create the Subscription Flow</h2><p>This flow creates and renews webhook subscriptions for all your lists.</p><h3 id="step-31-create-a-new-flow">Step 3.1: Create a New Flow</h3><h4 id="step-311-create-the-flow">Step 3.1.1: Create the Flow</h4><ol><li>In Power Automate, click <strong>+ Create</strong></li><li>Click <strong>Scheduled cloud flow</strong></li><li>Configure:</li><li><strong>Flow name</strong>: <code>Webhook Subscription Manager</code></li><li><strong>Starting</strong>: Select today's date</li><li><strong>Repeat every</strong>: <code>1</code> <code>Month</code></li><li>Click <strong>Create</strong></li></ol><hr><h3 id="step-32-initialize-variables">Step 3.2: Initialize Variables</h3><p>You need several variables for this flow.</p><h4 id="step-321-add-variable-for-headers">Step 3.2.1: Add Variable for Headers</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>header_nometa</code></li><li><strong>Type</strong>: Select <strong>Object</strong></li><li><strong>Value</strong>: </li></ol><h4 id="step-322-add-variable-for-flow-name">Step 3.2.2: Add Variable for Flow Name</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>flowName</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><h4 id="step-323-add-variable-for-notification-url">Step 3.2.3: Add Variable for Notification URL</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>notificationURL</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Paste the HTTP POST URL you copied from the Handler Flow</li></ol><h4 id="step-324-add-variable-for-expiration-date">Step 3.2.4: Add Variable for Expiration Date</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>expirationDateTime</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><h4 id="step-325-add-variable-for-subscription-id">Step 3.2.5: Add Variable for Subscription ID</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Initialize variable</code></li><li>Select <strong>Initialize variable</strong></li><li>Configure:</li><li><strong>Name</strong>: <code>SubscriptionID</code></li><li><strong>Type</strong>: Select <strong>String</strong></li><li><strong>Value</strong>: Leave empty</li></ol><hr><h3 id="step-33-get-the-sites-to-monitor">Step 3.3: Get the Sites to Monitor</h3><h4 id="step-331-get-items-from-sites-list">Step 3.3.1: Get Items from Sites List</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Get items</code></li><li>Select <strong>Get items</strong> (SharePoint)</li><li>Configure:</li><li><strong>Site Address</strong>: Your management site URL</li><li><strong>List Name</strong>: Select <code>Sites</code></li></ol><hr><h3 id="step-34-loop-through-each-site">Step 3.4: Loop Through Each Site</h3><h4 id="step-341-add-apply-to-each">Step 3.4.1: Add Apply to Each</h4><ol><li>Click <strong>+ New step</strong></li><li>Search for <code>Apply to each</code></li><li>Select <strong>Apply to each</strong></li><li>In <strong>Select an output from previous steps</strong>, select <code>value</code> from "Get items"</li></ol><hr><h3 id="step-35-get-lists-from-each-site">Step 3.5: Get Lists from Each Site</h3><p>Inside the "Apply to each" loop:</p><h4 id="step-351-query-lists-matching-your-criteria">Step 3.5.1: Query Lists Matching Your Criteria</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Click in the box, click <strong>Dynamic content</strong>, select <code>URL</code> from the Sites list</li><li><strong>Method</strong>: Select <strong>GET</strong></li><li><strong>Uri</strong>: </li><li><strong>Headers</strong>: </li><li><strong>Key</strong>: <code>Accept</code></li><li><strong>Value</strong>: <code>application/json; odata=nometadata</code></li></ol><p><strong>Customize the filter</strong>: Change <code>startswith(Title, 'contracts-')</code> to match your list naming pattern.</p><hr><h3 id="step-36-extract-list-ids">Step 3.6: Extract List IDs</h3><h4 id="step-361-add-select-action">Step 3.6.1: Add Select Action</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Select</code></li><li>Select <strong>Select</strong> (under "Data Operations")</li><li>Configure:</li><li><strong>From</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li><li>Click <strong>Switch to text mode</strong> (the icon with a "T")</li><li><strong>Map</strong>: Click <strong>Expression</strong> and enter:</li><li>Click <strong>OK</strong></li></ol><hr><h3 id="step-37-build-subscription-uris">Step 3.7: Build Subscription URIs</h3><h4 id="step-371-add-another-select-action">Step 3.7.1: Add Another Select Action</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Select</code></li><li>Select <strong>Select</strong></li><li>Configure:</li><li><strong>From</strong>: Select <code>Output</code> from the previous Select action</li><li>Click <strong>Switch to text mode</strong></li><li><strong>Map</strong>: Enter exactly (including quotes):</li></ol><p><strong>Note</strong>: If Power Automate removes the quotes when you save, add them back manually.</p><hr><h3 id="step-38-loop-through-each-subscription-uri">Step 3.8: Loop Through Each Subscription URI</h3><h4 id="step-381-add-nested-apply-to-each">Step 3.8.1: Add Nested Apply to Each</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Apply to each</code></li><li>Select <strong>Apply to each</strong></li><li>In <strong>Select an output from previous steps</strong>, select <code>Output</code> from the second Select action</li></ol><hr><h3 id="step-39-check-for-existing-subscriptions">Step 3.9: Check for Existing Subscriptions</h3><p>Inside the nested loop:</p><h4 id="step-391-get-existing-subscriptions">Step 3.9.1: Get Existing Subscriptions</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Select <code>URL</code> from Dynamic content (from the Sites list)</li><li><strong>Method</strong>: Select <strong>GET</strong></li><li><strong>Uri</strong>: Select <code>Current item</code> from Dynamic content (this is the subscription URI)</li><li><strong>Headers</strong>:</li><li><strong>Key</strong>: <code>Accept</code></li><li><strong>Value</strong>: <code>application/json; odata=nometadata</code></li></ol><h4 id="step-392-filter-to-this-flows-subscriptions">Step 3.9.2: Filter to This Flow's Subscriptions</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Filter array</code></li><li>Select <strong>Filter array</strong> (under "Data Operations")</li><li>Configure:</li><li><strong>From</strong>: Click <strong>Expression</strong> and enter:</li></ol><p>(Note: The action name may have a number like <code>_2</code> or <code>_3</code> – check your actual action name)</p><ul><li>Click <strong>OK</strong></li><li>In the condition:</li><li>Left field: Click <strong>Expression</strong> and enter: <code>item()?['clientState']</code></li><li>Middle: Select <strong>is equal to</strong></li><li>Right field: Select <code>flowName</code> variable</li></ul><h4 id="step-393-set-the-subscriptionid-variable">Step 3.9.3: Set the SubscriptionID Variable</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Set variable</code></li><li>Select <strong>Set variable</strong></li><li>Configure:</li><li><strong>Name</strong>: Select <code>SubscriptionID</code></li><li><strong>Value</strong>: Click <strong>Expression</strong> and enter:</li></ol><h4 id="step-394-extract-the-list-guid">Step 3.9.4: Extract the List GUID</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Compose</code></li><li>Select <strong>Compose</strong> (under "Data Operations")</li><li>Rename it to <code>Get_resource_id</code> (click the three dots, then "Rename")</li><li><strong>Inputs</strong>: Click <strong>Expression</strong> and enter:</li></ol><p>(Note: Check your actual loop name – it might be <code>Apply_to_each_2</code> or similar)</p><hr><h3 id="step-310-create-or-update-the-subscription">Step 3.10: Create or Update the Subscription</h3><h4 id="step-3101-add-a-condition">Step 3.10.1: Add a Condition</h4><ol><li>Click <strong>Add an action</strong></li><li>Search for <code>Condition</code></li><li>Select <strong>Condition</strong></li><li>Configure:</li><li>Left field: Click <strong>Expression</strong> and enter: <code>length(body('Filter_array'))</code></li><li>Middle: Select <strong>is greater than</strong></li><li>Right field: Enter <code>0</code></li></ol><hr><h3 id="step-311-configure-if-yes-update-existing-subscription">Step 3.11: Configure "If Yes" (Update Existing Subscription)</h3><h4 id="step-3111-update-the-subscription">Step 3.11.1: Update the Subscription</h4><ol><li>Click inside <strong>If yes</strong></li><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Select <code>URL</code> from the Sites list</li><li><strong>Method</strong>: Select <strong>PATCH</strong></li><li><strong>Uri</strong>: Click <strong>Expression</strong> and enter:</li><li><strong>Headers</strong>:</li><li><code>Accept</code>: <code>application/json; odata=nometadata</code></li><li><code>Content-Type</code>: <code>application/json; odata=nometadata</code></li><li><strong>Body</strong>:</li></ol><hr><h3 id="step-312-configure-if-no-create-new-subscription">Step 3.12: Configure "If No" (Create New Subscription)</h3><h4 id="step-3121-create-the-subscription">Step 3.12.1: Create the Subscription</h4><ol><li>Click inside <strong>If no</strong></li><li>Click <strong>Add an action</strong></li><li>Search for <code>Send an HTTP request to SharePoint</code></li><li>Select <strong>Send an HTTP request to SharePoint</strong></li><li>Configure:</li><li><strong>Site Address</strong>: Select <code>URL</code> from the Sites list</li><li><strong>Method</strong>: Select <strong>POST</strong></li><li><strong>Uri</strong>: Select <code>Current item</code> from Dynamic content (the subscription URI)</li><li><strong>Headers</strong>:</li><li><code>Accept</code>: <code>application/json; odata=nometadata</code></li><li><code>Content-Type</code>: <code>application/json; odata=nometadata</code></li><li><strong>Body</strong>:</li></ol><hr><h3 id="step-313-save-the-flow">Step 3.13: Save the Flow</h3><ol><li>Click <strong>Save</strong> in the top right corner</li><li>Verify the flow saves without errors</li></ol><hr><h2 id="part-4-initialize-the-timestamps-list">Part 4: Initialize the Timestamps List</h2><p>Before running the Subscription Flow, you need to add entries to the Timestamps list for each list you want to monitor.</p><h3 id="step-41-get-list-guids">Step 4.1: Get List GUIDs</h3><p>For each list you want to monitor:</p><ol><li>Navigate to the list in SharePoint</li><li>Click the <strong>gear icon</strong> (Settings) in the top right</li><li>Click <strong>List settings</strong></li><li>Look at the URL in your browser – find the part that says <code>List=%7B...%7D</code></li><li>The GUID is between <code>%7B</code> and <code>%7D</code> (these are encoded <code>{</code> and <code>}</code>)</li></ol><h3 id="step-42-add-entries-to-timestamps-list">Step 4.2: Add Entries to Timestamps List</h3><p>For each monitored list, add a row with the following values:</p><ul><li><strong>Title</strong>: A descriptive name, e.g. <code>Contracts-Sales</code></li><li><strong>listGUID</strong>: The GUID you copied in the previous step, e.g. <code>abc12345-...</code></li><li><strong>SiteURL</strong>: The full URL of the site where the list lives, e.g. <code>https://yourtenant.sharepoint.com/sites/sales</code></li><li><strong>LastModificationDateTime</strong>: Set this to today's date</li></ul><p>Repeat for every list you want to monitor. For instance, add a second row for <code>Contracts-HR</code> with its GUID and the HR site URL.</p><hr><h2 id="part-5-test-the-solution">Part 5: Test the Solution</h2><h3 id="step-51-test-the-handler-flow">Step 5.1: Test the Handler Flow</h3><ol><li>Open the Handler Flow</li><li>Click <strong>Test</strong> in the top right</li><li>Select <strong>Manually</strong></li><li>Click <strong>Test</strong></li><li>The flow will wait for a trigger</li></ol><h3 id="step-52-run-the-subscription-flow">Step 5.2: Run the Subscription Flow</h3><ol><li>Open the Subscription Flow</li><li>Click <strong>Test</strong> in the top right</li><li>Select <strong>Manually</strong></li><li>Click <strong>Test</strong></li><li>Click <strong>Run flow</strong></li></ol><p>If successful, the Subscription Flow will create webhook subscriptions, which will trigger the Handler Flow's validation.</p><h3 id="step-53-verify-subscriptions-were-created">Step 5.3: Verify Subscriptions Were Created</h3><ol><li>Check the Subscription Flow run history – all actions should show green checkmarks</li><li>Check the Handler Flow run history – you should see validation runs (these are normal)</li></ol><h3 id="step-54-test-a-real-change">Step 5.4: Test a Real Change</h3><ol><li>Go to one of your monitored SharePoint lists</li><li>Create or modify an item</li><li>Within a few minutes, the Handler Flow should trigger</li><li>Check the Handler Flow run history to verify it processed the change</li></ol><hr><h2 id="troubleshooting">Troubleshooting</h2><p><strong>"Failed to validate notification URL"</strong> — This means the Handler Flow is not responding to SharePoint's validation request. Make sure the Handler Flow is saved and enabled before running the Subscription Flow.</p><p><strong>Subscription Flow fails on the "Select" action</strong> — Power Automate has a known quirk where it strips the quotation marks from the mapping field when you save. Open the action, re-add the quotes manually, and save again.</p><p><strong>Handler Flow never triggers after setup</strong> — The webhook subscription has likely expired or was not created correctly. Open the Subscription Flow and run it manually to renew all subscriptions.</p><p><strong>No items returned in the Handler Flow</strong> — Check that the Timestamps list has correct entries for the list in question. If the <code>LastModificationDateTime</code> value is in the future or the <code>listGUID</code> doesn't match, the filter query will return no results.</p><p><strong>"Action name not found" errors in expressions</strong> — Power Automate auto-generates action names based on the action title, and appends numbers like <code>_2</code> or <code>_3</code> when there are duplicates. Open the action that precedes the failing expression and check its actual generated name, then update the expression to match.</p><hr>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Microsoft Resumes Marketing Recall Despite Internal Failure Assessment]]></title>
                    <description><![CDATA[A new Microsoft marketing campaign pitches 2026 as &quot;the moment for AI PCs&quot; and prominently features Recall as a key selling point. This comes just 18 days after Windows Central reported that Microsoft internally considers Recall a failure and is exploring reworking or renaming the feature.

💡Key Facts:]]></description>
                    <link>https://www.docupoint.eu/blog/microsoft-resumes-marketing-recall-despite-internal-failure-assessment/</link>
                    <guid isPermaLink="false">6999fab9256f2b0001032152</guid>

                        <category><![CDATA[Microsoft Recall]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sat, 21 Feb 2026 19:35:20 +0100</pubDate>


                    <content:encoded><![CDATA[<p>A new Microsoft marketing campaign pitches 2026 as "the moment for AI PCs" and prominently features Recall as a key selling point. This comes just 18 days after Windows Central reported that Microsoft internally considers Recall a failure and is exploring reworking or renaming the feature.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">💡</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Key Facts:</strong></b><br><b><strong style="white-space: pre-wrap;">Campaign message:</strong></b> "Recall: Search your digital memory by describing how you remember something"<br><b><strong style="white-space: pre-wrap;">Context:</strong></b> Internal failure assessment reported February 2 by Windows Central<br><b><strong style="white-space: pre-wrap;">Also notable:</strong></b> Recall has been absent from Windows release notes recently; Click to Do receives updates, but Recall itself is rarely mentioned<br><b><strong style="white-space: pre-wrap;">Enterprise angle:</strong></b> The marketing focuses entirely on consumer use cases with no mention of Purview integration</div></div><hr><p>The contradiction is striking. Internally, sources describe Recall as having failed, with the possibility of dropping the name entirely. Externally, the marketing machine continues to position it as a flagship Copilot+ PC feature. Windows Latest notes that Microsoft has been quietly adding features to Click to Do (Recall's companion feature) while avoiding direct references to Recall in release notes. The campaign suggests that Recall's marketing and product teams may not be aligned, or that Microsoft has decided to maintain the public narrative while reworking the feature behind the scenes. Either way, European organisations should treat Recall's current status and roadmap as uncertain.</p><p><strong>Sources:</strong> <a href="https://www.windowslatest.com/2026/02/20/microsoft-says-2026-is-the-moment-for-ai-pcs-touts-windows-11-recall-copilot-and-the-highest-standard-of-security/?ref=docupoint.eu">Windows Latest</a> · <a href="https://www.windowscentral.com/microsoft/windows-11/microsoft-is-reevaluating-its-ai-efforts-on-windows-11-plans-to-reduce-copilot-integrations-and-evolve-recall?ref=docupoint.eu">Windows Central</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[What Microsoft&#x27;s Danish Datacenters Actually Solve and What They Don&#x27;t]]></title>
                    <description><![CDATA[If a vendor tells you that storing data in a local datacenter equals data sovereignty — run. Data sovereignty is determined by the legal jurisdiction of the entity that operates the infrastructure, not by the postal code of the server. ]]></description>
                    <link>https://www.docupoint.eu/blog/what-microsofts-danish-datacenters-actually-solve-and-what-they-dont/</link>
                    <guid isPermaLink="false">6999f0e3256f2b00010320b8</guid>

                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[microsoft]]></category>
                        <category><![CDATA[GDPR]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sat, 21 Feb 2026 19:12:20 +0100</pubDate>

                        <media:content url="https://images.unsplash.com/photo-1737942546710-c33f2ddd0c6a?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDR8fHBhZGxvY2slMjBvbiUyMGZlbmNlfGVufDB8fHx8MTc3MTY5NzM0MHww&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1737942546710-c33f2ddd0c6a?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDR8fHBhZGxvY2slMjBvbiUyMGZlbmNlfGVufDB8fHx8MTc3MTY5NzM0MHww&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" alt="What Microsoft&#x27;s Danish Datacenters Actually Solve and What They Don&#x27;t"/> <div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-emoji">⚠️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">If a vendor tells you that storing data in a local datacenter equals data sovereignty, run.</strong></b> Data sovereignty is determined by the legal jurisdiction of the entity that operates the infrastructure, not by the postal code of the server. A Danish datacenter operated by a US corporation is subject to US law. That is not a nuance. It is the entire point.</div></div><p>Microsoft's Denmark East region launches in the first half of 2026. Denmark West, covering new facilities in Esbjerg and Varde, was announced in December 2025. Between 2023 and 2027, Microsoft is investing $3 billion in datacenter capacity on Danish soil. Brad Smith called it an investment that would "strengthen Europe's digital sovereignty."</p><p>The performance, residency, and sustainability benefits are real. For many Danish organisations, this is genuinely good news. But the sovereignty framing deserves scrutiny, because residency and sovereignty mean very different things.</p><h3 id="residency-vs-sovereignty">Residency vs. Sovereignty</h3><p>Data residency is about geography. Where does data physically sit? When Denmark East goes live, tenants who select that region will store data at rest in Denmark. Real capability, no asterisks.</p><p>Data sovereignty is about jurisdiction. Who can legally compel access to that data? Every authoritative definition, including Microsoft's own documentation, says the same thing: data sovereignty means data is subject to the laws of the nation where it resides, and that nation holds authority over access and disclosure.</p><p>One partner whitepaper recently redefined data sovereignty as "responsibility" and "making informed decisions you can stand behind in front of your board, citizens, customers, and authorities." That is good governance. It is not data sovereignty. When a vendor redefines sovereignty as accountability rather than jurisdictional control, they are sidestepping the one question that actually matters: which government can legally compel access to your data, and can you stop them?</p><h3 id="the-jurisdictional-reality">The Jurisdictional Reality</h3><p>Microsoft is a US corporation. Two pieces of US legislation follow that fact regardless of where the servers sit. The CLOUD Act (2018) authorises US authorities to compel US companies to produce data stored anywhere in the world. FISA Section 702 authorises surveillance of non-US persons through US companies, irrespective of server location. Its scope was expanded in April 2024 with a broader definition of "electronic communication service provider."</p><p>On June 10, 2025, Microsoft France's legal director Anton Carniaux testified under oath before the French Senate. Asked whether he could guarantee that EU-stored data would not be disclosed to US authorities, he answered: <em>"Non, je ne peux pas le garantir"</em>. No, I cannot guarantee that.</p><p>The EU and US have tried three times to create a stable legal basis for transatlantic data transfers. Safe Harbor fell in 2015. Privacy Shield in 2020. The current Data Privacy Framework rests on an executive order that any president can modify. In January 2025, the Trump administration removed three of five Privacy and Civil Liberties Oversight Board members, breaking a key DPF safeguard mechanism.</p><p>None of this makes Microsoft illegal or unusable. The DPF is in force. The EU Data Boundary is genuine engineering. For many organisations, Microsoft 365 remains a practical and lawful choice. But an EU datacenter does not equal EU data sovereignty.</p><h3 id="who-should-celebrate-and-who-should-be-cautious">Who should celebrate, and who should be cautious</h3><p>The value of Danish datacenters depends entirely on your regulatory context and data sensitivity.</p>
<!--kg-card-begin: html-->
<table style="width:100%; border-collapse:collapse; font-size:0.92em; line-height:1.5; table-layout:fixed;">
  <colgroup>
    <col style="width:auto;">
    <col style="width:27%;">
    <col style="width:27%;">
    <col style="width:27%;">
  </colgroup>
  <thead>
    <tr style="border-bottom:2px solid #1a1a1a;">
      <th style="padding:0.6em 0.8em; text-align:left;"></th>
      <th style="padding:0.6em 0.8em; text-align:left; font-weight:700;">Highly Regulated</th>
      <th style="padding:0.6em 0.8em; text-align:left; font-weight:700;">Regulated</th>
      <th style="padding:0.6em 0.8em; text-align:left; font-weight:700;">Standard Commercial</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e0e0e0; vertical-align:top;">
      <td style="padding:0.6em 0.8em; font-weight:600; white-space:nowrap;">Examples</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Defence, critical infrastructure, healthcare, core banking, government</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Pharma (GxP), legal, education, energy, insurance</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Professional services, retail, media, general enterprise</td>
    </tr>
    <tr style="border-bottom:1px solid #e0e0e0; vertical-align:top; background:#f9f9f9;">
      <td style="padding:0.6em 0.8em; font-weight:600; white-space:nowrap;">Latency benefit</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Significant for real-time systems and AI workloads</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Moderate in integration-heavy environments</td>
      <td style="padding:0.6em 0.8em;">Low to moderate</td>
    </tr>
    <tr style="border-bottom:1px solid #e0e0e0; vertical-align:top;">
      <td style="padding:0.6em 0.8em; font-weight:600; white-space:nowrap;">Residency benefit</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">High, meets localisation mandates</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">High, simplifies compliance</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Moderate, reduces audit complexity</td>
    </tr>
    <tr style="border-bottom:1px solid #e0e0e0; vertical-align:top; background:#f9f9f9;">
      <td style="padding:0.6em 0.8em; font-weight:600; white-space:nowrap;">Sovereignty gap</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;"><strong style="color:#c0392b;">Critical</strong> — CLOUD Act exposure may be disqualifying. Evaluate sovereign alternatives or customer-managed encryption.</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;"><strong style="color:#d4890a;">Significant</strong> — requires documented risk acceptance. DPIA must address US jurisdictional access.</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;"><strong style="color:#27864e;">Manageable</strong> — DPF provides current legal basis. Monitor stability.</td>
    </tr>
    <tr style="vertical-align:top; border-bottom:2px solid #1a1a1a;">
      <td style="padding:0.6em 0.8em; font-weight:600; white-space:nowrap;">Verdict</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Do not treat residency as sovereignty. Evaluate EU-owned alternatives for sensitive workloads.</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;">Use Danish datacenters for general workloads. Classify sensitive data separately.</td>
      <td style="padding:0.6em 0.8em; white-space:wrap;"><strong>Celebrate.</strong> Lower latency, simpler compliance, better sustainability. Adopt them.</td>
    </tr>
  </tbody>
</table>
<!--kg-card-end: html-->
<p>The problem is not the datacenters. The problem is when marketing leads highly regulated organisations to believe that residency solves sovereignty. It does not. The consequences of that misunderstanding land on the organisation, not the vendor.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Not sure where your organisation falls on this spectrum? Strator helps regulated Danish organisations assess their data, compliance, classifying workprocesses by sensitivity, and identifying which data can safely move to Danish datacenters and which requires stronger controls.
                        </div>
                    
                    
                        <a href="https://strator.com/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Contact Strator →
                        </a>
                        
                    </div>
                
            </div>
        </div><h3 id="the-danish-contradiction">The Danish Contradiction</h3><p>In June 2025, Denmark's Minister for Digitalisation Caroline Stage Olsen announced the Ministry would migrate from Microsoft Office 365 to LibreOffice, citing sovereignty concerns. Copenhagen and Aarhus are pursuing similar paths. Six months later, Microsoft announced its largest-ever Danish investment.</p><p>The Danish government understands that physical presence does not resolve jurisdictional control. They are diversifying away from Microsoft for sensitive workloads while welcoming the infrastructure investment. That posture, adopt the datacenters but reject the sovereignty narrative, is exactly right.</p><h3 id="what-would-real-sovereignty-require">What would real sovereignty require?</h3><p>Microsoft is not ignoring the problem. The EU Data Boundary, confidential computing, and customer-managed encryption keys represent genuine effort to reduce practical risk. None of them resolve the structural issue.</p><p>Customer-managed keys sound definitive. If you hold the keys, Microsoft cannot read the data. But anyone who has set up BitLocker with a Microsoft account has seen their recovery key silently uploaded to Microsoft's cloud. That is key escrow, not customer-managed encryption. Even with keys in external hardware security modules, the platform operator processes decrypted data in memory during use. A CLOUD Act order does not ask for your encryption keys. It compels Microsoft, as the infrastructure operator, to cooperate in producing data. If Microsoft has administrative access to the environment, that obligation can be fulfilled regardless of where your keys sit.</p><p>Confidential computing with trusted execution environments is designed to close that last gap. But you still trust the silicon vendor, the attestation chain, and the operator's implementation. These are meaningful mitigations. They are not sovereignty.</p><p>The only path to genuine sovereignty using Microsoft technology is to <strong>separate the operating entity from the US corporate parent.</strong> France understood this. In 2021, Orange and Capgemini created Bleu, a legally independent French company, majority-owned by French entities, operating datacenters physically isolated from Microsoft's global infrastructure, staffed entirely by French employees. Bleu licenses Microsoft technology but is not a Microsoft subsidiary. It is not subject to the CLOUD Act because it is not a US company.</p><p>For Microsoft to deliver real sovereignty in Europe, it would need to let go. Help establish legally independent EU entities that license its technology but operate without a US parent in the chain of command. Microsoft could retain minority ownership, but the operating entity must be European-owned, European-governed, and European-operated. The jurisdictional chain must be severed, not mitigated.</p><p>No US hyperscaler has done this at scale. The Bleu model comes with real tradeoffs: narrower services, slower feature rollout, higher cost. But it is the only model that addresses the actual problem. That, or get rid of the US CLOUD Act.</p><h3 id="what-to-do-now">What to do now</h3><p>If you are evaluating Microsoft's Danish datacenters, start here. Distinguish residency from sovereignty in your DPIA. Explicitly address CLOUD Act and FISA 702 exposure, even if the risk is acceptable for your data classification. Classify data by sensitivity: general business data on Danish infrastructure is a straightforward win, but patient records, classified data, or core banking systems require a harder conversation. And watch the DPF. If Schrems III materialises, the legal basis for US cloud providers processing EU data could be invalidated for the third time.</p><p>The Danish datacenters are a genuine improvement. For most organisations, they are worth adopting. They are not a sovereignty solution. And until someone builds a Danish Bleu, a legally independent, EU-governed entity operating Microsoft technology without a US parent in the chain, they never will be.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Need help navigating this? Strator has 15+ years of experience in information governance for regulated industries across Denmark. We help organisations build DPIAs that honestly address jurisdictional exposure, classify data by sensitivity, and design Microsoft 365 architectures that match their actual compliance requirements, not their vendor's marketing claims.
                        </div>
                    
                    
                        <a href="https://strator.com/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Talk to Strator →
                        </a>
                        
                    </div>
                
            </div>
        </div>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[The Lidl Cloud: How Europe&#x27;s Largest Retailer Is Building a Sovereign Hyperscaler]]></title>
                    <description><![CDATA[The Schwarz Group is investing €11 billion to build Europe&#x27;s first sovereign hyperscaler. I assess what STACKIT offers today, where it falls short, and whether it represents a viable migration path for organizations looking to leave Microsoft 365 and Azure.]]></description>
                    <link>https://www.docupoint.eu/blog/lidl-cloud-stackit-sovereign-hyperscaler-migration/</link>
                    <guid isPermaLink="false">69943474256f2b0001032037</guid>

                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[STACKIT]]></category>
                        <category><![CDATA[european-cloud]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Tue, 17 Feb 2026 12:00:32 +0100</pubDate>

                        <media:content url="https://images.unsplash.com/photo-1573164713988-8665fc963095?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDM5fHxkYXRhY2VudGVyfGVufDB8fHx8MTc3MTIzMjgxMHww&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1573164713988-8665fc963095?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDM5fHxkYXRhY2VudGVyfGVufDB8fHx8MTc3MTIzMjgxMHww&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" alt="The Lidl Cloud: How Europe&#x27;s Largest Retailer Is Building a Sovereign Hyperscaler"/> <p>Europe's largest retailer just broke ground on a €11 billion data center. Not to sell groceries online or optimize supply chains. To become Europe's first homegrown hyperscaler and challenge AWS, Azure, and Google Cloud on their own turf.</p><p>The Schwarz Group, the parent company behind Lidl and Kaufland, is building a 200MW, 100,000-GPU data center campus in Lübbenau, Germany, on the site of a decommissioned coal power plant south of Berlin. The first phase is scheduled for completion by the end of 2027. It is backed by €175 billion in annual retail revenue, strategic partnerships with SAP, Google, and German AI company Aleph Alpha, and an explicitly stated mission to end Europe's dependence on American cloud infrastructure.</p><p>For European companies currently evaluating their Microsoft 365 dependency, considering open-source alternatives like Nextcloud or Alfresco, or simply wondering whether a credible European IaaS/PaaS provider will ever exist, this changes the conversation.</p><hr><h2 id="from-supermarket-aisles-to-server-racks">From supermarket aisles to server racks</h2><p>Running 14,200 stores across 32 countries generates enormous volumes of sensitive data. When the Schwarz Group evaluated where to host it all, it concluded that no existing European cloud provider could meet its security and sovereignty requirements. And using AWS or Azure meant accepting the US CLOUD Act.</p><p>So they built their own. What started as an internal cloud platform in 2018 became STACKIT GmbH in 2023, then part of Schwarz Digits, a dedicated IT division employing around 7,500 people and generating €1.9 billion in annual revenue. The division also includes XM Cyber (cybersecurity), an investment in Aleph Alpha (AI), and partnerships with Wire (secure communications) and SAP.</p><p>The Lübbenau data center scales this internal capability into a genuine European hyperscaler serving external customers.</p><h2 id="what-stackit-offers-today">What STACKIT offers today</h2><p>STACKIT provides a solid IaaS and PaaS foundation: virtual machines, block and object storage, networking, managed Kubernetes (SKE), Cloud Foundry, and managed databases (PostgreSQL, MongoDB, OpenSearch). For organizations running workloads on Azure VMs or AWS EC2, this is directly comparable. For teams using Azure Kubernetes Service or AWS EKS, SKE is a credible alternative.</p><p>The critical gap is SaaS. STACKIT does not offer its own productivity suite. It is the infrastructure layer, not a drop-in replacement for Microsoft 365 or Google Workspace. The service catalog has perhaps 20-30 services compared to Azure's 200+, and the global presence is limited to Germany and Austria.</p><p>What makes the strategy interesting is that STACKIT is building a sovereign application ecosystem through partnerships.</p><h2 id="the-sovereign-workplace-ecosystem">The sovereign workplace ecosystem</h2><p>Rather than building an M365 competitor from scratch, Schwarz Digits has assembled a portfolio of partnerships:</p><p><strong>Google Workspace on STACKIT</strong> is hosted on STACKIT infrastructure with client-side encryption. The Schwarz Group is migrating its own 575,000 employees to this instance. It is a pragmatic improvement over American-controlled infrastructure, but it is not true digital sovereignty. Google remains a US company subject to the CLOUD Act and FISA Section 702. The keys to the data may be European; the keys to the software are not. For organizations pursuing genuine sovereignty, this is a stepping stone, not a destination.</p><p><strong>Wire</strong> is a Swiss-German end-to-end encrypted messaging platform using the MLS protocol. Already used by the Schwarz Group for board-level communications. Purpose-built for high-assurance scenarios and federated cross-organization communication.</p><p><strong>openDesk</strong> is the German government-backed open-source workplace suite (Nextcloud, Collabora Online, Element, OpenProject) available as SaaS on STACKIT. Primarily targeted at the public sector.</p><p><strong>SAP on STACKIT</strong> lets organizations run S/4HANA on STACKIT infrastructure within European jurisdiction through the RISE with SAP program.</p><p><strong>PhariaAI</strong> is Aleph Alpha's sovereign AI suite running natively on STACKIT, enabling organizations to train and deploy AI models without proprietary knowledge leaking into external training data.</p><h2 id="can-an-m365-company-migrate-to-stackit">Can an M365 company migrate to STACKIT?</h2><p>Yes, but it requires honest planning, not wishful thinking. Microsoft 365 is an integrated ecosystem where SharePoint, Teams, Exchange, OneDrive, Power Platform, Entra ID, and Purview are deeply intertwined. You cannot simply lift it and drop it onto STACKIT. You need to decompose it and find sovereign replacements for each capability.</p><p><strong>Document management and file storage</strong> is the most mature replacement path. Nextcloud Hub or Alfresco on STACKIT (VMs, Kubernetes, managed PostgreSQL backends) can replace SharePoint and OneDrive. Your files, metadata, and database all reside on GDPR-compliant infrastructure with no CLOUD Act exposure. STACKIT does not offer these as managed SaaS, so you deploy and manage the application yourself or use a partner.</p><p><strong>Email</strong> is the single biggest gap. Exchange Online is where Microsoft shines brightest, and STACKIT offers no managed email service. Self-hosting email (Open-Xchange, Zimbra) on STACKIT VMs means owning the entire operational burden: spam filtering, deliverability, backup, high availability, security patching, 24/7 monitoring. The savings from leaving Microsoft get consumed by the engineers needed to run it. For most organizations, email should be the last workload to migrate, not the first.</p><p><strong>Team communication</strong> depends on what you are already doing. If you are migrating to Nextcloud, start with <strong>Nextcloud Talk</strong>. It is included at no additional cost, supports encrypted video/audio calls, chat, screen sharing, and integrates natively with Nextcloud files, calendar, and tasks. For most internal communication, Talk is more than sufficient. Consider <strong>Wire</strong> as an additional layer only if you need high-assurance communications: board-level discussions, cross-organization federation, or regulatory scenarios where MLS protocol guarantees matter. Some organizations run both.</p><p><strong>Identity and access management</strong> catches organizations off guard. Those deeply integrated with Entra ID will need Keycloak or Univention Corporate Server on STACKIT. This is often the hidden blocker.</p><p><strong>Compliance and governance</strong> has no single open-source equivalent to Microsoft Purview. Retention policies, classification, eDiscovery, and audit trails need to be reconstructed using Nextcloud's or Alfresco's built-in capabilities, potentially supplemented by dedicated GRC tooling.</p><h3 id="the-realistic-migration-path">The realistic migration path</h3><p>The realistic path is a phased sovereignty transition over 12-24 months:</p><ol><li><strong>Assess and classify</strong> — Map your M365 and Azure estate. Classify every workload by sovereignty sensitivity.</li><li><strong>Migrate infrastructure</strong> — Move Azure VM and container workloads, databases, and networking to STACKIT.</li><li><strong>Migrate documents</strong> — Extract documents, metadata, permissions, and version history from SharePoint Online to Nextcloud or Alfresco on STACKIT. This is the hardest phase.</li><li><strong>Transition the productivity stack</strong> — Enable Nextcloud Talk, replace OneDrive with Nextcloud file sync, add Wire only if needed.</li><li><strong>Rebuild compliance</strong> — Reconstruct retention policies, classification schemes, and audit trails.</li><li><strong>Email (when ready)</strong> — Keep Exchange Online until a managed sovereign email service emerges.</li></ol><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Phase 3 is where most migrations succeed or fail, regardless of direction. Whether you are migrating out of SharePoint to a sovereign platform, consolidating legacy systems into SharePoint, or restructuring an existing SharePoint environment, the challenge is the same: every document, metadata schema, permission model, and version history must arrive in the right place. Strator plans the target information architecture and executes controlled document migrations for regulated organizations, ensuring nothing breaks in transit.
                        </div>
                    
                    
                        <a href="https://strator.dk/?ref=docupoint.eu" class="kg-cta-button kg-style-accent" style="color: #ffffff;">
                            Talk to Strator about your migration →
                        </a>
                        
                    </div>
                
            </div>
        </div><h2 id="why-the-%E2%82%AC11-billion-matters">Why the €11 billion matters</h2><p>The single biggest risk with European cloud alternatives has always been sustainability. Companies fear investing in a migration to a provider that might fail or stop growing. The Schwarz Group's commitment, backed by €175 billion in annual retail revenue, changes that calculus. This is not a venture-funded startup. The €8.5 billion allocated to IT infrastructure (primarily GPUs) positions STACKIT not just as an alternative hosting provider, but as a platform for AI training and inference at European scale. That matters increasingly as the EU AI Act requires demonstrable control over training data and model behavior.</p><h2 id="what-this-means-for-european-companies">What this means for European companies</h2><p><strong>For regulated industries (pharma, finance, healthcare, defense):</strong> The combination of STACKIT + SAP + sovereign Google Workspace + Wire + PhariaAI creates a complete sovereign technology stack that can meet GDPR, NIS2, DORA, and industry-specific compliance requirements without US cloud dependency. That did not exist two years ago.</p><p><strong>For companies running SharePoint and M365:</strong> STACKIT is not a platform you migrate SharePoint to directly. But it is the infrastructure that makes a migration to Nextcloud or Alfresco genuinely viable at enterprise scale, with the security and compliance backing large organizations require.</p><p><strong>For any European company worried about the CLOUD Act or unpredictable US policy changes:</strong> STACKIT offers an insurance policy. Even if you do not migrate today, a credible European hyperscaler means you have a realistic exit path.</p><h2 id="planning-the-information-architecture-is-the-real-work">Planning the information architecture is the real work</h2><p>The technology choice is only half the migration. The other half is information architecture: deciding where every document type, metadata schema, permission model, and retention policy lands on the target platform before you move a single file.</p><p>This is where migrations go wrong. Organizations arrive at the target platform without a clear plan for how their information should be structured. The result is a disorganized pile of files that technically migrated but practically broke every governance workflow the business depended on.</p><p>For regulated industries, this is not just an inconvenience. It is a compliance failure. GxP-regulated documents must maintain chain of custody. Retention policies must survive the transition. Sensitive and controlled documents must arrive in the correct location with the correct access controls, or the migration itself becomes a regulatory event.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Strator is a SharePoint specialist with 15+ years of experience in regulated industries. We migrate data into SharePoint, out of SharePoint, and between environments, and we optimize existing architectures to meet evolving compliance requirements. Whether you are planning a sovereignty migration or consolidating your current platform, Strator designs the target information architecture and ensures every controlled document arrives where it belongs, with metadata intact and audit trails preserved.
                        </div>
                    
                    
                        <a href="https://strator.dk/?ref=docupoint.eu" class="kg-cta-button kg-style-accent" style="color: #ffffff;">
                            Book a migration assessment →
                        </a>
                        
                    </div>
                
            </div>
        </div><h2 id="the-caveats">The caveats</h2><p><strong>Scale and maturity.</strong> STACKIT generated €1.9 billion in 2024, compared to AWS's $100+ billion. The service catalog is lean and the partner ecosystem is young.</p><p><strong>Vendor concentration risk.</strong> Moving from Microsoft dependency to Schwarz Group dependency is a dependency shift, not elimination. The use of open-source technologies (OpenStack, Kubernetes) at STACKIT's core mitigates this, since your workloads should be portable.</p><p><strong>Migration complexity is real.</strong> Leaving M365 requires organizational commitment, budget, change management, and patience. Companies should not underestimate the effort, but they should also not let complexity become a reason for inaction.</p><h2 id="the-european-cloud-just-got-real">The European cloud just got real</h2><p>"European digital sovereignty" has been a policy aspiration more than a practical reality for years. Gaia-X generated more PowerPoint decks than usable infrastructure. European cloud providers remained regional players with limited scale.</p><p>The Schwarz Group's €11 billion entry changes this. Not because STACKIT is ready to replace Azure today (it is not), but because there is now a European actor with the financial muscle and strategic commitment to build hyperscaler-grade infrastructure within European jurisdiction.</p><p>If you are running M365 or Azure workloads, now is the time to map your estate, classify your data by sovereignty sensitivity, and evaluate STACKIT alongside other European providers. The question is no longer whether European companies can leave Big Tech. It is whether they will start planning before circumstance forces their hand.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[FortiClient VPN on Hyprland Wayland The Complete Setup Guide]]></title>
                    <description><![CDATA[How to install and configure FortiClient VPN on Arch Linux with Hyprland and Wayland. Covers the right AUR package, gnome-keyring setup, and the XWayland workaround needed for SAML/SSO login to work.]]></description>
                    <link>https://www.docupoint.eu/blog/forticlient-vpn-on-hyprland-wayland-the-complete-setup-guide/</link>
                    <guid isPermaLink="false">6993135849431d0001e74348</guid>

                        <category><![CDATA[Linux]]></category>
                        <category><![CDATA[Hyprland]]></category>
                        <category><![CDATA[Wayland]]></category>
                        <category><![CDATA[VPN]]></category>
                        <category><![CDATA[FortiClient]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 16 Feb 2026 14:02:00 +0100</pubDate>

                        <media:content url="https://images.unsplash.com/photo-1590065707046-4fde65275b2e?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDl8fHZwbnxlbnwwfHx8fDE3NzEyNDY0NjJ8MA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1590065707046-4fde65275b2e?crop&#x3D;entropy&amp;cs&#x3D;tinysrgb&amp;fit&#x3D;max&amp;fm&#x3D;jpg&amp;ixid&#x3D;M3wxMTc3M3wwfDF8c2VhcmNofDl8fHZwbnxlbnwwfHx8fDE3NzEyNDY0NjJ8MA&amp;ixlib&#x3D;rb-4.1.0&amp;q&#x3D;80&amp;w&#x3D;2000" alt="FortiClient VPN on Hyprland Wayland The Complete Setup Guide"/> <p>If you're running Hyprland on Wayland and need to connect to a Fortinet SSL VPN with SAML/SSO, you're in for a rough ride. FortiClient on Linux has several undocumented issues on Wayland compositors, and the official documentation is essentially silent on the topic.</p><p>This guide covers every pitfall I've hit and how to solve them — from choosing the right package to getting the SAML login popup to actually appear.</p><h2 id="choosing-the-right-package">Choosing the Right Package</h2><p>On Arch Linux (and derivatives like CachyOS), there are three options in the AUR:</p><table>
<thead>
<tr>
<th>Package</th>
<th>Description</th>
<th>SSO Support</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>openfortivpn</code></td>
<td>Open-source CLI client</td>
<td>No native SAML — requires cookie workaround</td>
</tr>
<tr>
<td><code>forticlient</code></td>
<td>Full ZTNA edition</td>
<td>Yes, but <strong>blocks standalone VPN</strong> without EMS server</td>
</tr>
<tr>
<td><code>forticlient-vpn</code></td>
<td>VPN-only edition</td>
<td>Yes, works standalone</td>
</tr>
</tbody>
</table>
<p>The correct choice is <strong>forticlient-vpn</strong>. Here's why the others fail:</p><ul><li><strong>openfortivpn</strong> doesn't support SAML/SSO authentication natively. You'd need to extract an <code>SVPNCOOKIE</code> from a browser session manually — fragile and tedious.</li><li><strong>forticlient</strong> (the ZTNA edition) includes endpoint compliance features that require registration with a FortiClient EMS server. Without EMS, the VPN feature is locked with the error: <code>SSLVPN is disabled while registered to EMS</code>. If your organization doesn't provide an EMS endpoint, this package is a dead end.</li></ul><p>Install the VPN-only edition:</p><pre><code class="language-bash">paru -S forticlient-vpn</code></pre><p>Start and enable the service:</p><pre><code class="language-bash">sudo systemctl enable --now forticlient.service</code></pre><h2 id="the-secrets-service-requirement">The Secrets Service Requirement</h2><p>FortiClient stores VPN credentials through the <code>org.freedesktop.secrets</code> D-Bus interface. Without a secrets service running, <strong>you cannot save VPN profiles</strong> — the GUI save button simply does nothing, with no error message.</p><p>If you're on a KDE-based setup, you might have <code>kwallet</code> installed but not necessarily exposing the freedesktop secrets interface. The most reliable option is <code>gnome-keyring</code>:</p><pre><code class="language-bash">sudo pacman -S gnome-keyring</code></pre><p>Start the secrets component:</p><pre><code class="language-bash">gnome-keyring-daemon --start --components=secrets</code></pre><p>Verify it's registered on D-Bus:</p><pre><code class="language-bash">dbus-send --session --print-reply \
  --dest=org.freedesktop.DBus \
  /org/freedesktop/DBus \
  org.freedesktop.DBus.ListNames 2&gt;&amp;1 | grep secrets</code></pre><p>You should see <code>org.freedesktop.secrets</code> in the output.</p><h3 id="making-it-persistent">Making It Persistent</h3><p>To ensure gnome-keyring starts automatically on login, add it to your PAM configuration. The <code>gnome-keyring</code> package typically installs PAM hooks automatically, but if your session doesn't go through a standard display manager (common with Hyprland), you may need to start it in your Hyprland config:</p><pre><code class="language-ini"># ~/.config/hypr/hyprland.conf
exec-once = gnome-keyring-daemon --start --components=secrets</code></pre><p>After setting up the secrets service, restart FortiClient:</p><pre><code class="language-bash">sudo systemctl restart forticlient.service</code></pre><p>You should now be able to save VPN profiles in the GUI.</p><h2 id="the-wayland-problem-buttons-dont-work">The Wayland Problem: Buttons Don't Work</h2><p>Here's where it gets truly frustrating. You've installed the right package, set up the secrets service, saved your VPN profile — and when you click <strong>Connect</strong>, nothing happens. No SAML popup. No error. The GUI shows "Connecting" and sits there forever.</p><p>The SSL VPN log at <code>/var/log/forticlient/sslvpn.log</code> reveals the issue:</p><pre><code>[sslvpn:INFO] main:1781 State: Logging in
[sslvpn:DEBG] main:1689 Message to UI: 8
[sslvpn:DEBG] main:1707 90 bytes sent.</code></pre><p>The VPN backend sends a message to the GUI (the SAML login window request), but the Electron-based GUI running natively on Wayland fails to open the popup. The buttons themselves may also not register clicks properly.</p><h3 id="the-fix-force-xwayland">The Fix: Force XWayland</h3><p>FortiClient's Electron GUI doesn't work correctly as a native Wayland client on Hyprland. The solution is to force it to run under XWayland using the <code>--ozone-platform=x11</code> flag:</p><pre><code class="language-bash">WAYLAND_DISPLAY="" DISPLAY=:1 \
  /opt/forticlient/gui/FortiClient --ozone-platform=x11</code></pre><p>You can verify it's running under XWayland by checking:</p><pre><code class="language-bash">hyprctl clients | grep -A15 "FortiClient"</code></pre><p>Look for <code>xwayland: 1</code> in the output. If it says <code>xwayland: 0</code>, it's running as a native Wayland client and will have the input/popup issues.</p><h3 id="permanent-wrapper-script">Permanent Wrapper Script</h3><p>Create a wrapper script so you don't have to remember the flags:</p><pre><code class="language-bash">#!/usr/bin/env bash
# ~/.local/bin/forticlient-vpn
# Force FortiClient to run under XWayland on Hyprland
export WAYLAND_DISPLAY=""
export DISPLAY="${DISPLAY:-:1}"
exec /opt/forticlient/gui/FortiClient --ozone-platform=x11 "$@"</code></pre><p>Make it executable:</p><pre><code class="language-bash">chmod +x ~/.local/bin/forticlient-vpn</code></pre><p>You can also create a desktop entry to override the default launcher:</p><pre><code class="language-ini">[Desktop Entry]
Type=Application
Name=FortiClient VPN
Exec=env WAYLAND_DISPLAY="" DISPLAY=:1 /opt/forticlient/gui/FortiClient --ozone-platform=x11
Icon=FortiClient
Terminal=false
Categories=Network;VPN;</code></pre><h2 id="summary-checklist">Summary Checklist</h2><p>If you're setting up FortiClient VPN on Hyprland from scratch, here's the complete sequence:</p><ol><li>Install <code>forticlient-vpn</code> (not <code>forticlient</code> ZTNA edition)</li><li>Install <code>gnome-keyring</code> and ensure <code>org.freedesktop.secrets</code> is on D-Bus</li><li>Start the FortiClient service: <code>sudo systemctl enable --now forticlient.service</code></li><li>Launch FortiClient with <code>--ozone-platform=x11</code> to force XWayland</li><li>Add your VPN profile in the GUI (server, port, SAML authentication)</li><li>Click <strong>Connect</strong> — the SAML login popup should now appear</li></ol><h2 id="troubleshooting">Troubleshooting</h2><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">SSLVPN is disabled while registered to EMS</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">You installed the ZTNA edition (</span><code spellcheck="false" style="white-space: pre-wrap;"><span>forticlient</span></code><span style="white-space: pre-wrap;">). Switch to </span><code spellcheck="false" style="white-space: pre-wrap;"><span>forticlient-vpn</span></code><span style="white-space: pre-wrap;"> — the VPN-only package that works without an EMS server.</span></p></div>
        </div><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">Cannot save VPN profiles</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">No secrets service is running. Install </span><code spellcheck="false" style="white-space: pre-wrap;"><span>gnome-keyring</span></code><span style="white-space: pre-wrap;"> and start it with </span><code spellcheck="false" style="white-space: pre-wrap;"><span>gnome-keyring-daemon --start --components=secrets</span></code><span style="white-space: pre-wrap;">. Verify that </span><code spellcheck="false" style="white-space: pre-wrap;"><span>org.freedesktop.secrets</span></code><span style="white-space: pre-wrap;"> appears on D-Bus.</span></p></div>
        </div><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">Connect button does nothing / SAML popup doesn't appear</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">FortiClient is running as a native Wayland client. Force XWayland by launching with </span><code spellcheck="false" style="white-space: pre-wrap;"><span>--ozone-platform=x11</span></code><span style="white-space: pre-wrap;"> and unsetting </span><code spellcheck="false" style="white-space: pre-wrap;"><span>WAYLAND_DISPLAY</span></code><span style="white-space: pre-wrap;">. Verify with </span><code spellcheck="false" style="white-space: pre-wrap;"><span>hyprctl clients</span></code><span style="white-space: pre-wrap;"> that </span><code spellcheck="false" style="white-space: pre-wrap;"><span>xwayland: 1</span></code><span style="white-space: pre-wrap;"> is shown.</span></p></div>
        </div><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">Keyring is locked</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">The gnome-keyring needs to be unlocked at login. Ensure it's integrated with PAM or started in your Hyprland config with </span><code spellcheck="false" style="white-space: pre-wrap;"><span>exec-once = gnome-keyring-daemon --start --components=secrets</span></code><span style="white-space: pre-wrap;">.</span></p></div>
        </div><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">No log output in /var/log/forticlient/sslvpn.log</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">Enable VPN logging in FortiClient settings (under the gear icon), or check that the FortiClient service is running: </span><code spellcheck="false" style="white-space: pre-wrap;"><span>systemctl status forticlient.service</span></code><span style="white-space: pre-wrap;">.</span></p></div>
        </div><div class="kg-card kg-toggle-card" data-kg-toggle-state="close">
            <div class="kg-toggle-heading">
                <h4 class="kg-toggle-heading-text"><span style="white-space: pre-wrap;">Stuck on ‘Connecting’ after SAML login completes</span></h4>
                <button class="kg-toggle-card-icon" aria-label="Expand toggle to read content">
                    <svg id="Regular" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path class="cls-1" d="M23.25,7.311,12.53,18.03a.749.749,0,0,1-1.06,0L.75,7.311"></path>
                    </svg>
                </button>
            </div>
            <div class="kg-toggle-content"><p><span style="white-space: pre-wrap;">The VPN gateway’s TLS certificate is being rejected silently. Check </span><code spellcheck="false" style="white-space: pre-wrap;"><span>~/.config/FortiClient/logs/main.log</span></code><span style="white-space: pre-wrap;"> for </span><code spellcheck="false" style="white-space: pre-wrap;"><span>FCT_VPN_INVALID_CERTIFICATE</span></code><span style="white-space: pre-wrap;">. The GUI fails to display the certificate acceptance dialog, so the connection hangs until timeout.</span></p><p><span style="white-space: pre-wrap;">Fix by disabling the certificate warning in FortiClient’s SQLite config databases:</span></p><pre><code class="language-bash">sudo systemctl stop forticlient

sudo sqlite3 /var/lib/forticlient/config.db \
  "UPDATE vpn SET value='0' WHERE config='sslvpn.options.warn_invalid_server_certificate';"

sudo sqlite3 /opt/forticlient/.config.db.init \
  "UPDATE vpn SET value='0' WHERE config='sslvpn.options.warn_invalid_server_certificate';"

sudo systemctl start forticlient</code></pre><p><span style="white-space: pre-wrap;">This setting may reset after FortiClient package updates.</span></p></div>
        </div>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Hyprlock Crash Protection: Three Layers of Lock Screen Safety on Hyprland]]></title>
                    <description><![CDATA[Hyprlock can crash during suspend/resume cycles, leaving your Hyprland session unlocked. Here&#x27;s how to build a three-layer defense with a watchdog script, systemd-managed hypridle, and a resume guard — so your lock screen always comes back.]]></description>
                    <link>https://www.docupoint.eu/blog/hyprlock-crash-protection-three-layers-of-lock-screen-safety-on-hyprland/</link>
                    <guid isPermaLink="false">698d996b49898900010c823e</guid>

                        <category><![CDATA[Hyprland]]></category>
                        <category><![CDATA[Linux]]></category>
                        <category><![CDATA[Security]]></category>
                        <category><![CDATA[Wayland]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Thu, 12 Feb 2026 10:22:00 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/hyprlock-feature.jpg" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/hyprlock-feature.jpg" alt="Hyprlock Crash Protection: Three Layers of Lock Screen Safety on Hyprland"/> <p>If you use Hyprland as your Wayland compositor, you’ve probably adopted <strong>hyprlock</strong> as your lock screen and <strong>hypridle</strong> as your idle daemon. It’s a clean, well-integrated setup — until one morning you wake up to find hyprlock has crashed overnight and your session is wide open.</p><p>This guide walks through why hyprlock crashes happen and how to build a three-layer defense that keeps your session protected no matter what.</p><h2 id="the-problem">The Problem</h2><p>Here’s a typical lock-and-sleep workflow on Hyprland:</p><ol><li>You lock your screen (<code>Super+Ctrl+L</code> or a dedicated lock key)</li><li>After a few minutes of inactivity, monitors turn off (DPMS)</li><li>After 30 minutes, the system suspends</li><li>Hours later, something wakes the system (Bluetooth event, USB device, scheduled wake)</li><li>hyprlock should show the lock screen — but it has crashed</li></ol><p>The crash typically happens during the suspend/resume cycle. AMD GPUs (especially integrated Radeon graphics) are particularly prone to this: the GPU resources hyprlock holds become invalid when the display hardware powers down and back up.</p><p>When hyprlock crashes, you’re left with an unlocked desktop. If you’re away from your machine, that’s a security problem.</p><h2 id="the-solution-three-layers-of-protection">The Solution: Three Layers of Protection</h2><p>Rather than hoping for a bug fix, we can build resilience into the system. Each layer catches failures the previous one might miss.</p><h3 id="layer-1-hyprlock-watchdog-script">Layer 1: Hyprlock Watchdog Script</h3><p>The most important piece. Instead of running hyprlock directly, we wrap it in a script that monitors its exit code and restarts it on crash.</p><p>Create <code>~/.config/hypr/scripts/hyprlock-watchdog.sh</code>:</p><pre><code class="language-bash">#!/usr/bin/env bash
# -----------------------------------------------
# Hyprlock Watchdog
# Wraps hyprlock and restarts it if it crashes.
# If it keeps crashing, suspends the system as a
# safety measure to protect the unlocked session.
# -----------------------------------------------

MAX_RESTARTS=5
RESTART_DELAY=1
CRASH_WINDOW=60  # Reset crash counter if stable for this many seconds

# Don't start if hyprlock is already running
if pidof hyprlock &gt; /dev/null 2&gt;&amp;1; then
    exit 0
fi

crash_count=0

while [ $crash_count -lt $MAX_RESTARTS ]; do
    start_time=$(date +%s)

    hyprlock
    exit_code=$?

    # Exit code 0 = normal unlock by user
    if [ $exit_code -eq 0 ]; then
        exit 0
    fi

    end_time=$(date +%s)
    runtime=$((end_time - start_time))

    # If hyprlock ran for a while before crashing, reset the counter
    # (it was stable, this is likely a new/different issue)
    if [ $runtime -ge $CRASH_WINDOW ]; then
        crash_count=1
    else
        crash_count=$((crash_count + 1))
    fi

    logger -t hyprlock-watchdog "hyprlock crashed with exit code $exit_code after ${runtime}s (crash $crash_count/$MAX_RESTARTS)"
    notify-send -u critical "Lock Screen" "hyprlock crashed (exit $exit_code). Restarting... ($crash_count/$MAX_RESTARTS)"

    sleep $RESTART_DELAY
done

# Exhausted restart attempts — suspend to protect the session
logger -t hyprlock-watchdog "hyprlock crashed $MAX_RESTARTS times in rapid succession. Suspending system."
notify-send -u critical "Lock Screen" "hyprlock keeps crashing. Suspending system for safety."
sleep 2
systemctl suspend
</code></pre><p>Make it executable:</p><pre><code class="language-bash">chmod +x ~/.config/hypr/scripts/hyprlock-watchdog.sh
</code></pre><p><strong>How it works:</strong></p><ul><li>When hyprlock exits with code 0 (user unlocked successfully), the watchdog exits too</li><li>When hyprlock crashes (non-zero exit), the watchdog restarts it immediately</li><li>If hyprlock ran for over 60 seconds before crashing, the crash counter resets (it was a one-off, not a crash loop)</li><li>If hyprlock crashes 5 times in rapid succession, the watchdog gives up and <strong>suspends the system</strong> — better to suspend than leave the session exposed</li><li>Every crash is logged via <code>logger</code> (check with <code>journalctl -t hyprlock-watchdog</code>) and shown as a notification</li></ul><h3 id="layer-2-systemd-managed-hypridle">Layer 2: Systemd-Managed Hypridle</h3><p>By default, most Hyprland setups start hypridle via <code>exec-once</code> in the Hyprland config. This is fire-and-forget: if hypridle crashes, it’s gone and your idle/lock/suspend chain is broken.</p><p>Hyprland ships a systemd user service at <code>/usr/lib/systemd/user/hypridle.service</code> with <code>Restart=on-failure</code>. If we use this instead, systemd will automatically restart hypridle when it crashes.</p><p><strong>Step 1:</strong> Comment out the exec-once line in your autostart config (<code>~/.config/hypr/conf/autostart.conf</code>):</p><pre><code class="language-conf"># hypridle is now managed by systemd (systemctl --user enable --now hypridle.service)
# exec-once = hypridle
</code></pre><p><strong>Step 2:</strong> Enable and start the systemd service:</p><pre><code class="language-bash"># Enable it (starts automatically on future logins)
systemctl --user enable hypridle.service

# Start it now (for the current session)
systemctl --user start hypridle.service

# Kill the old exec-once instance if it's still running
# Check PIDs first:
pgrep -a hypridle
# Kill the one that ISN'T the systemd-managed one (lower PID, usually)
kill &lt;old-pid&gt;
</code></pre><p><strong>Step 3:</strong> Verify:</p><pre><code class="language-bash">systemctl --user status hypridle.service
</code></pre><p>You should see <code>Active: active (running)</code> and <code>Restart: on-failure</code>.</p><h3 id="layer-3-resume-guard-in-hypridle">Layer 3: Resume Guard in Hypridle</h3><p>The final layer addresses the most dangerous moment: waking up from suspend. This is when hyprlock is most likely to crash (GPU resources are reinitialized, display state changes).</p><p>Update your <code>~/.config/hypr/hypridle.conf</code> general section:</p><pre><code class="language-conf">general {
    lock_cmd = pidof hyprlock || ~/.config/hypr/scripts/hyprlock-watchdog.sh
    before_sleep_cmd = loginctl lock-session
    after_sleep_cmd = hyprctl dispatch dpms on &amp;&amp; (pidof hyprlock &gt; /dev/null || loginctl lock-session)
}
</code></pre><p>The key changes:</p><ul><li><strong><code>lock_cmd</code></strong> now uses the watchdog wrapper instead of plain hyprlock</li><li><code><strong>after_sleep_cmd</strong></code> now does two things: turns on the display AND checks if hyprlock is still alive. If hyprlock crashed during resume, it triggers <code>loginctl lock-session</code>, which fires the <code>lock_cmd</code> again (launching the watchdog with a fresh hyprlock)</li></ul><h3 id="bonus-consistent-keybindings">Bonus: Consistent Keybindings</h3><p>If your keybindings call <code>hyprlock</code> directly, they bypass the watchdog. Update them to use <code>loginctl lock-session</code> instead, which goes through hypridle’s <code>lock_cmd</code>:</p><p>In <code>~/.config/hypr/conf/keybindings/default.conf</code>:</p><pre><code class="language-conf"># Before (bypasses watchdog):
# bind = $mainMod CTRL, L, exec, hyprlock
# bind = , XF86Lock, exec, hyprlock

# After (goes through hypridle's lock_cmd → watchdog):
bind = $mainMod CTRL, L, exec, loginctl lock-session
bind = , XF86Lock, exec, loginctl lock-session
</code></pre><p>If you have a <code>power.sh</code> script that calls <code>hyprlock</code> directly for its <code>lock</code> action, you can update that too — or just rebind the key to skip the script entirely.</p><h2 id="the-complete-flow">The Complete Flow</h2><p>Here’s what happens now when you lock your PC and go to bed:</p><ol><li><strong>You press Super+Ctrl+L</strong> → <code>loginctl lock-session</code> fires</li><li><strong>Hypridle catches it</strong> → runs <code>lock_cmd</code> → starts watchdog → starts hyprlock</li><li><strong>8 minutes idle</strong> → brightness dims to 10%</li><li><strong>10 minutes idle</strong> → (already locked, no-op)</li><li><strong>11 minutes idle</strong> → monitors turn off (DPMS)</li><li><strong>30 minutes idle</strong> → system suspends (<code>before_sleep_cmd</code> locks session again for safety)</li><li><strong>Morning: something wakes the PC</strong> → <code>after_sleep_cmd</code> runs:</li><li>Turns on DPMS</li><li>Checks if hyprlock is alive</li><li>If not → <code>loginctl lock-session</code> → watchdog → fresh hyprlock</li><li><strong>If hyprlock crashes during resume</strong> → watchdog catches it, restarts immediately</li><li><strong>If hyprlock keeps crashing</strong> → system suspends as a safety net</li></ol><p>At every point, something is watching something else. There’s no single point of failure.</p><h2 id="verifying-your-setup">Verifying Your Setup</h2><p>After making all the changes:</p><pre><code class="language-bash"># Reload Hyprland config
hyprctl reload

# Verify hypridle is running via systemd
systemctl --user status hypridle.service

# Test locking
loginctl lock-session

# Check watchdog logs after a lock/unlock cycle
journalctl -t hyprlock-watchdog --no-pager

# Monitor in real-time (in a separate terminal before locking)
journalctl -t hyprlock-watchdog -f
</code></pre><h2 id="troubleshooting">Troubleshooting</h2><p><strong>Hypridle won’t start via systemd:</strong> Check that <code>WAYLAND_DISPLAY</code> is set in your environment. The service requires it (<code>ConditionEnvironment=WAYLAND_DISPLAY</code>). If you’re having issues, run <code>systemctl --user show-environment | grep WAYLAND</code>.</p><p><strong>Two hypridle processes running:</strong> You probably forgot to kill the old exec-once instance or forgot to comment it out. Run <code>pgrep -a hypridle</code> and kill the one not managed by systemd.</p><p><strong>Lock screen never appears after resume:</strong> Check <code>journalctl --user -u hypridle.service</code> for errors. Make sure the <code>after_sleep_cmd</code> syntax is correct (the <code>pidof</code> check needs <code>/dev/null</code> redirection).</p><p><strong>Watchdog suspends immediately:</strong> If hyprlock keeps crashing in a loop (5 times), the watchdog suspends for safety. Check <code>journalctl -t hyprlock-watchdog</code> for the exit codes. Common causes: GPU driver issues (try updating <code>mesa</code>/<code>amdgpu</code>), or Wayland protocol mismatches (update hyprlock).</p><h2 id="summary">Summary</h2>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Layer</th>
<th>Protects Against</th>
<th>Mechanism</th>
</tr>
</thead>
<tbody>
<tr>
<td>Watchdog script</td>
<td>hyprlock crashes</td>
<td>Restarts hyprlock on non-zero exit, suspends after repeated failures</td>
</tr>
<tr>
<td>Systemd hypridle</td>
<td>hypridle crashes</td>
<td><code>Restart=on-failure</code> in the systemd service</td>
</tr>
<tr>
<td>Resume guard</td>
<td>Crash during wake from suspend</td>
<td><code>after_sleep_cmd</code> checks for hyprlock and re-locks if missing</td>
</tr>
<tr>
<td>Consistent keybindings</td>
<td>Manual lock bypassing watchdog</td>
<td>All lock paths go through <code>loginctl lock-session</code> → hypridle → watchdog</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>The system went from “one crash = exposed session” to “multiple independent safety nets.” Your lock screen might still crash — but now something is always watching, ready to restart it or suspend the machine before your session is left unprotected.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Microsoft&#x27;s Danish Datacenters and the Copilot Surprise: What European Companies Need to Know]]></title>
                    <description><![CDATA[Microsoft enabled Anthropic&#x27;s Claude in Copilot — outside the EU Data Boundary. A single admin toggle can send your data to US infrastructure. Here&#x27;s what European companies need to check now.]]></description>
                    <link>https://www.docupoint.eu/blog/microsoft-denmark-datacenters-eu-residency-illusion/</link>
                    <guid isPermaLink="false">698cfc50734df70001838701</guid>

                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[microsoft]]></category>
                        <category><![CDATA[copilot]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 11 Feb 2026 23:23:20 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/photo-1451187580459-43490279c0fa-1.jpeg" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/photo-1451187580459-43490279c0fa-1.jpeg" alt="Microsoft&#x27;s Danish Datacenters and the Copilot Surprise: What European Companies Need to Know"/> <p>Microsoft is building big in Denmark. In December 2020, the company announced its first Danish datacenter region, "Denmark East," covering sites in the Capital Region and Zealand. After five years of construction, that region is set to launch in the first half of 2026. Then, in December 2025, Microsoft announced a second region: "West Denmark," with three new facilities across Varde and Esbjerg municipalities, described as the company's largest single investment in its 36-year Danish history. Between 2023 and 2027 alone, Microsoft is committing $3 billion to datacenter capacity on Danish soil, and the West Denmark expansion will push that figure higher still.</p><p>For European IT leaders, the narrative looks like a win. Microsoft services running on Danish soil. Local jobs. Carbon-free energy. One step closer to keeping European data in Europe.</p><p>Then, on January 7, 2026, something else happened. And most organisations missed it entirely.</p><h3 id="the-quiet-change-inside-copilot">The quiet change inside Copilot</h3><p>On that date, Microsoft enabled Anthropic's Claude AI models as a subprocessor across Microsoft 365 Copilot. For commercial tenants outside the EU, the toggle was set to <strong>ON by default</strong>. No action required. No notification to end users. Just a new AI model processing their data alongside OpenAI's GPT.</p><p>The features powered by Anthropic's Claude include Microsoft 365 Copilot in web, desktop, and mobile, the Researcher agent, Copilot Studio, Power Platform, Agent Mode in Excel, and the Word, Excel, and PowerPoint agents. These are not marginal features. They are core productivity tools that millions of knowledge workers use daily.</p><p>Here is the critical detail: <strong>Anthropic models are explicitly excluded from Microsoft's EU Data Boundary.</strong> <a href="https://learn.microsoft.com/en-us/copilot/microsoft-365/connect-to-ai-subprocessor?ref=docupoint.eu">Microsoft's own documentation</a> states it plainly: <em>"Anthropic models deployed in Microsoft offerings are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments."</em></p><p>For EU/EFTA and UK tenants, Microsoft set the toggle to OFF by default. A responsible decision. But the toggle exists. And it only takes one Global Administrator, perhaps under pressure to give users access to the latest Copilot features, perhaps without fully understanding the data residency implications, to flip it on.</p><h3 id="what-happens-when-the-toggle-gets-flipped">What happens when the toggle gets flipped</h3><p>When an EU tenant administrator enables Anthropic as a Microsoft subprocessor, the organisation is explicitly opting out of EU Data Boundary protections for data processed by those models. The data no longer needs to stay within EU/EEA infrastructure. Anthropic processes data across US, European, Asian, and Australian infrastructure, with storage in US data centres.</p><p>This is not a bug. Microsoft has been transparent about it. The information is available in the admin centre and in their documentation. But "transparent" and "widely understood" are not the same thing. How many IT administrators in Danish SMBs have reviewed Microsoft's subprocessor documentation? How many DPOs have been consulted before the toggle decision?</p><p>The risk is compounded by the fact that users see no indication of which AI model is processing their prompt in most Copilot experiences. An employee using Copilot in Word does not know, and cannot easily determine, whether their document content is being processed by OpenAI (within the EU Data Boundary) or by Anthropic (outside it). The admin made a single decision in a settings panel. The user is unaware.</p><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-emoji">⚠️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">This toggle is not reversible.</strong></b> Enabling Anthropic and later switching it off stops <i><em class="italic" style="white-space: pre-wrap;">future</em></i> data from leaving the EU, but every prompt and document already processed by Anthropic has been sent to US infrastructure (reportedly AWS). That data cannot be un-processed, recalled, or deleted through Microsoft's standard compliance tools. GDPR Article 17 (right to erasure) against a US-hosted subprocessor of a subprocessor has no established precedent. A single admin decision, requiring no DPO approval and no impact assessment, can create an irreversible compliance event. The off switch is not an undo button.</div></div><h3 id="even-without-anthropic-the-datacenter-illusion">Even without Anthropic: the datacenter illusion</h3><p>Even with the Anthropic toggle safely in the OFF position, there is a deeper structural issue that Microsoft's Danish datacenters do not resolve.</p><p>Microsoft is a US corporation. Its Danish subsidiaries, the entities that will operate those Esbjerg, Varde, and Capital Region facilities, are controlled by a US parent company. Two pieces of US legislation make this distinction between <em>where the data sits</em> and <em>where the company is incorporated</em> critically important:</p><p><strong>FISA Section 702</strong> authorises US intelligence agencies to compel US companies to provide access to communications data of non-US persons. It applies to the company, not to the server. A Microsoft datacenter in Denmark is as reachable under FISA 702 as one in Virginia.</p><p><strong>The CLOUD Act</strong> (2018) makes this explicit: US law enforcement can compel US companies to disclose data stored on servers outside the United States. The data does not need to be in the US. The company does.</p><p>The EU-US Data Privacy Framework (DPF), adopted in 2023, provides the current legal basis for this processing. But its two predecessors, Safe Harbor (invalidated 2015, <em>Schrems I</em>) and Privacy Shield (invalidated 2020, <em>Schrems II</em>), were struck down by the Court of Justice of the European Union for the same fundamental reason: US surveillance law provides inadequate protection for EU data subjects. The DPF rests on an executive order that can be modified by any future US president. A legal challenge, commonly referred to as <em>Schrems III</em>, is widely expected.</p><p>None of this makes Microsoft illegal or unusable. The DPF is in force. Microsoft's EU Data Boundary is a genuine engineering effort. For most European organisations, Microsoft 365 is the practical and lawful choice.</p><p>But <strong>EU datacenter does not equal EU data sovereignty</strong>. And your governance should reflect that.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Strator has spent 25 years helping European organisations manage, classify, and govern their documents, from SharePoint migrations to GDPR compliance. If you're not sure how these jurisdictional issues affect your specific setup, we can help you figure it out.
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Talk to Strator
                        </a>
                        
                    </div>
                
            </div>
        </div><h3 id="the-multi-model-future">The multi-model future</h3><p>What makes the Anthropic integration particularly important is that it signals a direction, not just an incident. Microsoft's Business and Industry Copilot President Charles Lamanna framed it as giving customers "the flexibility to use Anthropic models too." Copilot is becoming a multi-model orchestrator, routing different tasks to different AI providers based on capability, not geography.</p><p>Today it is Anthropic. Tomorrow it could be another provider. The AI service your users interact with is no longer a single model from a single provider with a single set of data residency commitments. It is a platform that routes tasks behind the scenes, and each route may have different jurisdictional characteristics.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">"We use Microsoft Copilot" is no longer an answer to where your data is processed.</strong></b> Copilot is not one product with one data boundary. It is a platform that routes your prompts and documents to different AI providers, with different data residency commitments, depending on the feature, the task, and a single admin setting in your tenant. Your data staying inside Microsoft's control is no longer guaranteed by the fact that you are using Microsoft's product. If your compliance posture assumes Copilot = Microsoft = EU Data Boundary, that assumption is already out of date.</div></div><h3 id="where-does-your-data-actually-go-ai-vendor-overview">Where does your data actually go? AI vendor overview</h3><p>To understand the real picture, you need to know where each major AI provider processes data, and where that provider is incorporated.</p><hr><p><em>Green = EU-headquartered provider. Yellow = EU residency available or conditional. Red = no EU data residency.</em></p><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Microsoft 365 Copilot (OpenAI-powered features)</strong></b><br>HQ: United States · EU Data Residency: Yes (EU Data Boundary). Prompts and responses processed within EU for eligible tenants. Covers standard Copilot in Word, Excel, PowerPoint, Outlook, Teams.</div></div><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Microsoft 365 Copilot (Anthropic-powered features)</strong></b><br>HQ: United States · EU Data Residency: No. Researcher, Copilot Studio agents, Agent Mode in Excel, Word/Excel/PowerPoint agents. <b><strong style="white-space: pre-wrap;">Explicitly excluded from EU Data Boundary.</strong></b> OFF by default for EU tenants.</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">OpenAI (direct)</strong></b><br>HQ: United States · EU Data Residency: Enterprise only. EU residency via <code spellcheck="false" style="white-space: pre-wrap;">eu.api.openai.com</code> for enterprise API customers. ChatGPT Enterprise/Education can be configured for EU. Consumer plans (Plus, Pro, Team): no EU residency.</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Azure OpenAI</strong></b><br>HQ: United States · EU Data Residency: Yes (Data Zone EUR). Data Zone Standard (EUR) = EU-only processing. Regional deployment (e.g. Sweden Central) = single-region. Global deployment = may route anywhere (not suitable for EU-sensitive data).</div></div><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Anthropic Claude (direct)</strong></b><br>HQ: United States · EU Data Residency: No. No EU data residency for any direct service (claude.ai, API). EU processing available only through Amazon Bedrock (eu-west-1, eu-central-1) or Google Vertex AI (europe-west regions).</div></div><div class="kg-card kg-callout-card kg-callout-card-yellow"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Google Gemini / Vertex AI</strong></b><br>HQ: United States · EU Data Residency: Vertex only. Vertex AI supports EU-region deployment. Gemini consumer products: no EU residency guarantee.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Mistral AI</strong></b><br>HQ: France · EU Data Residency: Yes. EU-headquartered. API and Le Chat processed on EU infrastructure. Outside US jurisdiction entirely.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Aleph Alpha</strong></b><br>HQ: Germany · EU Data Residency: Yes. EU-headquartered. Luminous models with EU-only processing. Outside US jurisdiction entirely.</div></div><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Self-hosted (Llama, Mistral open-weights, etc.)</strong></b><br>EU Data Residency: Depends on where you host. EU cloud providers (Hetzner, OVH, Scaleway) = strongest sovereignty. AWS/Azure/GCP EU regions = US parent company still applies.</div></div><p>The pattern here is clear: EU data residency from a US company is technically real but legally fragile. EU data residency from an EU company is structurally sound. Self-hosted models give you the most control but require the most investment.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Navigating this landscape is what Strator does. With 25 years in document management and data governance across Microsoft 365 environments, we help organisations understand which vendor options match their risk profile and build the classification to enforce it.
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Talk to us
                        </a>
                        
                    </div>
                
            </div>
        </div><h3 id="what-you-should-do-now">What you should do now</h3><p><strong>1. Check the toggle.</strong> Log into the Microsoft 365 admin centre, go to Copilot, then Settings, Data access, AI providers operating as Microsoft subprocessors. Verify that Anthropic is disabled if your organisation requires EU Data Boundary compliance. Only a Global Administrator can change this setting.</p><p><strong>2. Document the decision.</strong> Whether you keep Anthropic off or turn it on, document the rationale. Your DPO should be involved. If you enable it, record that you are consciously accepting data processing outside the EU Data Boundary and update your ROPA accordingly.</p><p><strong>3. Classify your data.</strong> Not all data carries the same risk. Public marketing content processed by Anthropic outside the EU is a very different situation from internal HR documents or client contract details. A proper data classification, covering what can be processed by AI, under what conditions, and through which providers, is the foundation of governance in a multi-model world.</p><p><strong>4. Monitor the subprocessor list.</strong> Microsoft can add new AI subprocessors. Review your tenant's subprocessor settings quarterly. Set a calendar reminder. Do not assume today's configuration is permanent.</p><p><strong>5. Have a contingency plan.</strong> If the EU-US Data Privacy Framework is invalidated, every European organisation using Microsoft, OpenAI, Google, or any other US-headquartered cloud provider will need to reassess. Know which workloads can move to EU-headquartered providers. Start evaluating alternatives now, not when the CJEU ruling drops.</p><h3 id="the-uncomfortable-truth">The uncomfortable truth</h3><p>Microsoft investing billions in Danish infrastructure is genuinely good for Denmark. More local datacenters mean lower latency, local jobs, and better disaster recovery. Nobody is suggesting that European organisations should stop using Microsoft.</p><p>But European IT leaders need to understand what they are actually buying. A datacenter in Denmark gives you proximity. It gives you performance. It gives you a flag on a map that looks reassuring in a board presentation.</p><p>It does not give you sovereignty. Sovereignty requires that the data is beyond the legal reach of a foreign government, and as long as the company operating the datacenter is incorporated in the United States, that is not the case.</p><p>The organisations that understand this today, that classify their data, configure their admin toggles deliberately, and build contingency plans, will be the ones that navigate what comes next without scrambling.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal kg-cta-no-dividers   " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            Not sure where to start? Data classification for AI access is complex, but it does not have to be overwhelming. Strator helps European organisations classify their data, configure their Microsoft 365 environments, and build governance that actually works.
                        </div>
                    
                    
                        <a href="https://strator.dk/kontakt?ref=docupoint.eu" class="kg-cta-button " style="background-color: #15803d; color: #ffffff;">
                            Contact Strator
                        </a>
                        
                    </div>
                
            </div>
        </div>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[News Web Part &quot;See All&quot; Gets Mosaic Layout and AI Features]]></title>
                    <description><![CDATA[SharePoint News web part &quot;See all&quot; page refreshed with dynamic mosaic grid layout. AI-powered features available for users with Microsoft 365 Copilot license. GA rolling out late February to mid-March 2026.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/news-web-part-see-all-gets-mosaic-layout-and-ai-features/</link>
                    <guid isPermaLink="false">6990f9da49431d0001e74231</guid>

                        <category><![CDATA[Radar]]></category>
                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[SharePoint Online]]></category>
                        <category><![CDATA[Microsoft 365 Copilot]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 09 Feb 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>The SharePoint News web part’s “See all” page is getting a visual refresh with a dynamic mosaic grid layout and new AI-powered features for Copilot-licensed users. The rollout was paused in December 2025 and is now resuming, with GA expected late February to mid-March 2026.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>GA rollout:</strong> Late February to mid-March 2026 (Worldwide, GCC, GCCH, DoD)<br><strong>What changes:</strong> "See all" opens a mosaic grid layout instead of the current list view<br><strong>AI features:</strong> Available only to users with a Microsoft 365 Copilot license<br><strong>Core behavior:</strong> Unchanged. Same content, same permissions, new visual presentation<br><strong>Action required:</strong> None. Applies automatically to all News web parts</div></div><hr><p>The mosaic layout improves visual hierarchy and readability when browsing news. The AI-powered features (available only to Copilot-licensed users) add smart capabilities to how news is surfaced. This is one of several places where Microsoft is quietly gating new functionality behind Copilot licensing. Organizations without Copilot licenses still get the improved layout, just without the AI layer.</p><p><strong>Sources:</strong> <a href="https://mc.merill.net/message/MC1182713?ref=docupoint.eu">MC1182713</a> · <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?id=499654&ref=docupoint.eu">Roadmap 499654</a> · <a href="https://supersimple365.com/sharepoint-news-web-part-is-getting-a-new-see-all-experience/?ref=docupoint.eu">Super Simple 365</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Claude Opus 4.6: How AI Agents Boost Enterprise Document Management]]></title>
                    <description><![CDATA[Anthropic&#x27;s Claude Opus 4.6 brings a 1M token context window, parallel agent teams, and deep office integration. For document management professionals, this is a practical efficiency leap — and human expertise matters more than ever.]]></description>
                    <link>https://www.docupoint.eu/blog/claude-opus-4-6-ai-agents-boost-enterprise-document-management/</link>
                    <guid isPermaLink="false">698598e0df8a9200018c4b3a</guid>

                        <category><![CDATA[AI]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[Field Notes]]></category>
                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[News]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sat, 07 Feb 2026 09:57:36 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/Claude-Opus-4.6-When-AI-Agents-Boosts-Enterprise-Software.jpg" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/Claude-Opus-4.6-When-AI-Agents-Boosts-Enterprise-Software.jpg" alt="Claude Opus 4.6: How AI Agents Boost Enterprise Document Management"/> <p>On February 5, 2026, Anthropic released Claude Opus 4.6. It is a major update to their flagship AI model, and it brings capabilities that matter directly to anyone working with enterprise document management.</p><p>Not a paradigm shift. A solid step forward in what AI agents can practically do with documents, spreadsheets, and enterprise content. For organizations running SharePoint, Nextcloud, Documentum, or other DMS platforms, the update opens real efficiency gains if you know how to apply them.</p><hr><h2 id="what-opus-46-brings-to-the-table">What Opus 4.6 brings to the table</h2><h3 id="one-million-token-context-window">One million token context window</h3><p>Previous Opus models processed 200,000 tokens, roughly 500 pages of text. Opus 4.6 extends this to one million tokens in beta, approximately 750,000 words.</p><p>For document management, this is the most relevant upgrade. A model with this context window can hold an entire migration scope: all source metadata, target mappings, and exception rules in a single working session. No chunking, no summarization loss, no context switching between batches. You describe the full picture, and the model reasons across it.</p><p>On the MRCR v2 benchmark, which tests retrieval accuracy in large contexts, Opus 4.6 scored 76% compared to 18.5% for Sonnet 4.5. That is the difference between a model that accepts large inputs and one that actually finds what you need inside them.</p><h3 id="agent-teams">Agent teams</h3><p>Claude can now split a task across multiple parallel agents, each handling a piece and coordinating with the others. Combined with Cowork, the desktop agent Anthropic launched in January 2026, this means non-technical users can describe an outcome ("audit these three SharePoint sites for retention policy compliance") and let multiple agents work on it simultaneously.</p><p>For document-heavy operations, parallel execution is practical. An agent team can review a document library, flag exceptions, draft a summary report, and prepare remediation steps concurrently rather than sequentially.</p><h3 id="128000-token-output">128,000 token output</h3><p>Previous output limits forced the model to break large deliverables into multiple requests. Opus 4.6 can generate up to 128,000 tokens in a single response, roughly 96,000 words. A complete migration plan, a full compliance report, or a complete set of metadata mapping documentation can be produced in one pass.</p><h3 id="adaptive-effort-controls">Adaptive effort controls</h3><p>The model now adjusts its reasoning depth based on task complexity, and developers can set explicit effort levels. A simple document classification task does not need the same computational investment as a regulatory compliance analysis. Organizations can optimize for cost without sacrificing quality where it matters.</p><h3 id="context-compaction">Context compaction</h3><p>A beta feature that lets the model summarize its own older context during long-running tasks. For multi-hour operations like processing an entire document library or conducting cross-reference analysis across thousands of files, compaction prevents the model from losing track of earlier work.</p><hr><h2 id="the-office-integration-layer">The office integration layer</h2><p>Opus 4.6 arrives alongside expanded integrations that make Claude a practical participant in daily document work.</p><p><strong>Claude in PowerPoint</strong> launches in research preview, integrating directly into PowerPoint as a side panel. The model reads existing layouts and fonts to match corporate templates, useful for generating stakeholder presentations from migration data or compliance findings.</p><p><strong>Claude in Excel</strong> receives substantial upgrades for working with spreadsheet data, formulas, and analysis directly within Excel. For metadata inventories, permission matrices, and content type mappings, this turns Excel from a manual tool into a collaborative workspace.</p><p>Combined with <strong>Cowork</strong> for file system operations and <strong>Claude in Chrome</strong> for browser-based research, Anthropic is building a complete workspace agent. For document management professionals, this means the AI does not replace your tools. It operates alongside them, handling the repetitive parts while you focus on the decisions that require judgment.</p><hr><h2 id="what-this-means-for-document-management">What this means for document management</h2><p>This is where the practical value lives. Opus 4.6 does not change what document management is. It changes how efficiently you can do it, if you bring the right expertise.</p><h3 id="migration-planning-and-execution">Migration planning and execution</h3><p>Every data migration starts with the same problem: understanding what you have, where it needs to go, and what will break along the way. Source inventories. Metadata mappings. Content type transformations. Permission structures that need to be rebuilt. Exception rules for edge cases.</p><p>Traditionally, this analysis happens in stages. You inventory one site collection, map its metadata, document exceptions, then move to the next. With a million-token context window, a model can hold the entire scope simultaneously. Upload the complete source inventory, the target information architecture, and the migration rules, and the model can identify conflicts, flag unmapped content types, and draft transformation rules across the full dataset.</p><p>This does not eliminate the need for a migration specialist. It means the specialist spends less time on inventory and mapping mechanics and more time on the decisions that actually matter: which content structures to preserve, which to consolidate, and how to handle the hundreds of small exceptions that break automated migrations.</p><p>At <a href="https://strator.dk/?ref=docupoint.eu">Strator</a>, we have run data migrations for some of Denmark's largest organizations across pharmaceuticals, finance, and healthcare. The pattern is always the same: 80% of the work is systematic and repeatable, 20% requires human judgment shaped by years of experience with specific platforms, regulatory requirements, and organizational politics. AI agents handle the 80% faster. The 20% is where consultants earn their value.</p><h3 id="compliance-and-governance">Compliance and governance</h3><p>Regulated industries (pharmaceuticals under GxP and EMA requirements, finance under DORA and MiFID II, healthcare under patient data regulations) need continuous verification that their document management meets requirements. Retention policies, sensitivity labels, access permissions, and audit trails all require regular review.</p><p>Agent teams that work in parallel can scan document libraries, verify retention labels against policy, flag permission anomalies, and generate exception reports. Tasks that take a compliance team days to perform manually can be drafted in hours.</p><p>But the AI generates findings. A qualified professional validates them. In regulated environments, the signature on a compliance report carries legal weight. The AI cannot sign. A GxP-trained document management specialist can, because they understand not just what the label says but why it was applied, what regulatory context drove that decision, and what consequences follow from changing it.</p><p>This is where the human knowledge layer becomes essential. An AI agent can tell you that 47 documents in a validation folder have incorrect retention labels. It takes a regulatory specialist to determine whether those documents are superseded validation protocols that should have been archived, active records that were mislabeled during migration, or legacy content that predates the current retention policy entirely. Each scenario requires a different remediation path, and choosing wrong has audit consequences.</p><h3 id="daily-operations-and-content-processing">Daily operations and content processing</h3><p>Beyond large projects, Opus 4.6 improves day-to-day document operations. The combination of large context and substantial output means practical tasks become faster.</p><p>Summarizing meeting series into decision logs. Extracting action items from project correspondence. Classifying incoming documents against an information architecture. Generating metadata suggestions for content that was uploaded without proper tagging. Drafting standard operating procedures from existing process descriptions.</p><p>None of these tasks are new. Document management professionals do them every week. The difference is that an AI agent can handle the first draft, and a professional can review, adjust, and approve it. The review takes minutes instead of the hours the drafting would have taken.</p><h3 id="the-collaboration-model">The collaboration model</h3><p>The most productive way to think about Opus 4.6 is not as a replacement for expertise but as an amplifier. A junior consultant with AI assistance can produce first-draft deliverables at a speed that previously required senior-level efficiency. A senior consultant can focus their time on the judgment calls, client relationships, and strategic decisions that AI cannot replicate.</p><p>At <a href="https://strator.dk/?ref=docupoint.eu">Strator</a>, we see this in practice. Our consultants carry deep knowledge of SharePoint, regulated industries, and enterprise information management built over years of implementation work. That knowledge does not become less valuable when AI gets better. It becomes more valuable, because the bottleneck shifts from "can we process this data fast enough" to "do we understand what this data means in context."</p><p>AI provides speed. Human expertise provides direction. The combination is where real efficiency gains happen.</p><div class="kg-card kg-signup-card kg-width-regular kg-style-accent" data-lexical-signup-form="" style="; display: none;">
            
            <div class="kg-signup-card-content">
                
                <div class="kg-signup-card-text ">
                    <h2 class="kg-signup-card-heading" style="color: #ffffff;">Sign up for DocuPoint newsletter</h2>
                    
                    
        <form class="kg-signup-card-form" data-members-form="signup">
            
            <div class="kg-signup-card-fields">
                <input class="kg-signup-card-input" id="email" data-members-email="" type="email" required="true" placeholder="Your email">
                <button class="kg-signup-card-button " style="background-color: #000000;color: #ffffff;" type="submit">
                    <span class="kg-signup-card-button-default">Subscribe</span>
                    <span class="kg-signup-card-button-loading"><svg xmlns="http://www.w3.org/2000/svg" height="24" width="24" viewBox="0 0 24 24">
        <g stroke-linecap="round" stroke-width="2" fill="currentColor" stroke="none" stroke-linejoin="round" class="nc-icon-wrapper">
            <g class="nc-loop-dots-4-24-icon-o">
                <circle cx="4" cy="12" r="3"></circle>
                <circle cx="12" cy="12" r="3"></circle>
                <circle cx="20" cy="12" r="3"></circle>
            </g>
            <style data-cap="butt">
                .nc-loop-dots-4-24-icon-o{--animation-duration:0.8s}
                .nc-loop-dots-4-24-icon-o *{opacity:.4;transform:scale(.75);animation:nc-loop-dots-4-anim var(--animation-duration) infinite}
                .nc-loop-dots-4-24-icon-o :nth-child(1){transform-origin:4px 12px;animation-delay:-.3s;animation-delay:calc(var(--animation-duration)/-2.666)}
                .nc-loop-dots-4-24-icon-o :nth-child(2){transform-origin:12px 12px;animation-delay:-.15s;animation-delay:calc(var(--animation-duration)/-5.333)}
                .nc-loop-dots-4-24-icon-o :nth-child(3){transform-origin:20px 12px}
                @keyframes nc-loop-dots-4-anim{0%,100%{opacity:.4;transform:scale(.75)}50%{opacity:1;transform:scale(1)}}
            </style>
        </g>
    </svg></span>
                </button>
            </div>
            <div class="kg-signup-card-success" style="color: #ffffff;">
                Email sent! Check your inbox to complete your signup.
            </div>
            <div class="kg-signup-card-error" style="color: #ffffff;" data-members-error=""></div>
        </form>
        
                    <p class="kg-signup-card-disclaimer" style="color: #ffffff;">Get the articles right in your inbox. 100% free</p>
                </div>
            </div>
        </div><hr><h2 id="the-digital-sovereignty-dimension">The digital sovereignty dimension</h2><p>There is one important consideration that European organizations should keep in mind.</p><p>Opus 4.6 introduces US data residency as an option, at a 10% price premium. European data residency is not currently available. Every prompt, every document processed by Claude, every agent team coordinating across your files is processed on US infrastructure.</p><p>For most document management tasks (working with public content, internal process documents, or non-sensitive operational data) this is perfectly workable. But for organizations subject to GDPR, NIS2, or DORA processing personal data, health records, or regulated content, the data residency question needs a clear answer before deployment.</p><h3 id="practical-recommendations">Practical recommendations</h3><p><strong>Classify before you connect.</strong> Before granting any AI agent access to document libraries, classify the content by sensitivity. Public and internal-use documents are generally fine. Confidential, personal, or regulated data requires assessment, and may require on-premises or EU-hosted alternatives.</p><p><strong>Understand what EU hosting solves and what it does not.</strong> Anthropic may eventually offer European data residency. For many organizations, that could be sufficient, provided they classify their content carefully and manage what the AI is allowed to access. If your data is not subject to strict regulatory controls, EU-hosted infrastructure combined with proper access governance is a reasonable path forward.</p><p>For regulated industries where data must never leave the organization's domain, tenant, or control (pharmaceuticals under GxP, finance under DORA, healthcare under patient data regulations) the issue is not where the servers are. As long as Anthropic is a US-incorporated, US-controlled company, it remains subject to US legal frameworks including FISA Section 702, the CLOUD Act, and related provisions. These grant US authorities the ability to compel access to data regardless of where it is physically stored. EU hosting on US-controlled infrastructure does not resolve this. The capability is impressive. The jurisdictional reality makes it incompatible with European regulatory obligations for controlled data.</p><p><strong>Consider a DPIA regardless.</strong> Even for non-sensitive use cases, deploying Cowork or API-based agent teams for document processing likely triggers a Data Protection Impact Assessment under GDPR Article 35. Conduct it proactively. It will force the right conversations about what data goes where, and that clarity benefits the organization whether or not AI agents are involved.</p><div class="kg-card kg-cta-card kg-cta-bg-blue kg-cta-immersive kg-cta-no-dividers kg-cta-has-img  " data-layout="immersive">
            
            <div class="kg-cta-content">
                
                    <div class="kg-cta-image-container">
                        <a href="mailto: info@strator.com"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/02/Transformation.png" alt="CTA Image" data-image-dimensions="1920x1080"></a>
                    </div>
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            If you need help assessing your document management strategy, particularly in regulated environments where compliance and data sovereignty matter, Strator has the experience to guide that conversation. We work with Denmark's largest organizations across pharmaceuticals, finance, and healthcare, and we understand both the technology and the regulatory landscape.
                        </div>
                    
                    
                        <a href="mailto: info@strator.com" class="kg-cta-button kg-style-accent" style="color: #ffffff;">
                            Get in touch
                        </a>
                        
                    </div>
                
            </div>
        </div><hr><h2 id="pricing">Pricing</h2><p>Opus 4.6 maintains the same API pricing as its predecessor: $5 per million input tokens and $25 per million output tokens. Processing the full one-million-token context window costs $5. Generating a full 128K token output costs approximately $3.20.</p><p>For consumer access through claude.ai, Opus 4.6 is available on Pro ($20/month), Max ($100-200/month), Team, and Enterprise plans. Cowork is available on all paid plans.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Dark Mode Comes to SharePoint Admin Center]]></title>
                    <description><![CDATA[SharePoint admin center gets dark mode toggle, rolling out mid-to-late February 2026. Optional, no impact to end users or existing settings.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/dark-mode-comes-to-sharepoint-admin-center/</link>
                    <guid isPermaLink="false">6990f9da49431d0001e74227</guid>

                        <category><![CDATA[Radar]]></category>
                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[SharePoint Online]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Fri, 06 Feb 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>The SharePoint admin center is getting a dark mode toggle, aligning it with other Microsoft 365 admin portals that already support dark themes. Rolling out mid-to-late February 2026 for Worldwide and GCC tenants.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Rollout:</strong> Mid-February to late February 2026<br><strong>Scope:</strong> Worldwide and GCC<br><strong>How to enable:</strong> Toggle in the top-right corner of the SharePoint admin center<br><strong>Impact:</strong> Admin-only; no effect on end users or site settings<br><strong>Action required:</strong> None. Optional feature, light mode remains default</div></div><hr><p>This is separate from the dark site themes (Dark Teal, Dark Blue) that became available for SharePoint sites in December 2025. That change affected how site visitors see pages; this change affects how admins experience the admin center itself. A small quality-of-life update for admins who prefer darker interfaces or work in low-light environments.</p><p><strong>Sources:</strong> <a href="https://mc.merill.net/message/MC1228330?ref=docupoint.eu">MC1228330</a> · <a href="https://www.neowin.net/news/stop-the-eye-strain-sharepoint-admin-center-finally-joins-microsoft-365-dark-mode/?ref=docupoint.eu">Neowin</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Security Chief Bell Replaced, Secure Future Initiative at Risk]]></title>
                    <description><![CDATA[Microsoft has replaced Charlie Bell as Executive Vice President of Security with Hayete Gallot, a former Google Cloud executive whose background is in sales and customer experience. The change raises questions about the future of the Secure Future Initiative, the framework under which Recall was rearchitected with VBS Enclaves, encryption,]]></description>
                    <link>https://www.docupoint.eu/blog/security-chief-bell-replaced-secure-future-initiative-at-risk/</link>
                    <guid isPermaLink="false">6999fa40256f2b0001032141</guid>

                        <category><![CDATA[microsoft]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 04 Feb 2026 19:32:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft has replaced Charlie Bell as Executive Vice President of Security with Hayete Gallot, a former Google Cloud executive whose background is in sales and customer experience. The change raises questions about the future of the Secure Future Initiative, the framework under which Recall was rearchitected with VBS Enclaves, encryption, and opt-in controls.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><b><strong style="white-space: pre-wrap;">Key Facts:</strong></b><br><b><strong style="white-space: pre-wrap;">Who's out:</strong></b> Charlie Bell, who built Microsoft's Security, Compliance, Identity, and Management organization and drove the Secure Future Initiative<br><b><strong style="white-space: pre-wrap;">Who's in:</strong></b> Hayete Gallot, most recently President of Customer Experience at Google Cloud<br><b><strong style="white-space: pre-wrap;">Nadella's framing:</strong></b> Focused on "go-to-market efforts," "strong Purview adoption," and "continued customer growth"<br><b><strong style="white-space: pre-wrap;">What's missing:</strong></b> No language about the importance of building secure products<br><b><strong style="white-space: pre-wrap;">External pressure gone:</strong></b> The US Cyber Safety Review Board, which forced Microsoft's 2024 security reckoning, has been disbanded</div></div><hr><p>Bell joined Microsoft in 2021 to fix chronic security failures, but faced internal resistance. It took a damning CSRB report into the 2023 Chinese email breach to give him real authority. Under Bell, Recall was rearchitected from its disastrous 2024 launch into a genuinely more secure product with encrypted local storage and VBS Enclaves. Now that Bell has moved to an individual contributor role and the CSRB no longer exists, the external and internal forces that drove Microsoft's security improvements have both weakened. Lawfare's Tom Uren warns Microsoft's goal may be shifting from making secure products to selling security products. For European organisations evaluating Microsoft 365 security commitments, this leadership change warrants close attention.</p><p><strong>Sources:</strong> <a href="https://blogs.microsoft.com/blog/2026/02/04/updates-in-two-of-our-core-priorities/?ref=docupoint.eu">Official Microsoft Blog</a> · <a href="https://www.lawfaremedia.org/article/microsoft-forgoes-its-secure-future?ref=docupoint.eu">Lawfare</a> · <a href="https://www.cnbc.com/2026/02/04/microsoft-brings-back-hayete-gallot-to-run-security-new-role-for-bell.html?ref=docupoint.eu">CNBC</a> · <a href="https://www.windowscentral.com/microsoft/microsoft-engineering-quality-hayete-gallot-new-security-chief?ref=docupoint.eu">Windows Central</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Microsoft Internally Considers Recall a Failure, Explores Rework]]></title>
                    <description><![CDATA[Windows Central reports that Microsoft internally views Recall as a failure and is exploring reworking or renaming the feature as part of a broader AI strategy pullback on Windows 11.]]></description>
                    <link>https://www.docupoint.eu/blog/microsoft-internally-considers-recall-a-failure-explores-rework/</link>
                    <guid isPermaLink="false">6985adafdf8a9200018c4b84</guid>

                        <category><![CDATA[Microsoft Recall]]></category>
                        <category><![CDATA[copilot]]></category>
                        <category><![CDATA[AI Strategy]]></category>
                        <category><![CDATA[Windows 11]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 02 Feb 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft internally considers Recall's current implementation a failure and is exploring ways to rework or rename the feature, according to a Windows Central report citing sources familiar with the company's plans.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Internal assessment:</strong> Microsoft views Recall as having "failed" in its current form<br><strong>Options explored:</strong> Rework the feature entirely, possibly drop the "Recall" name<br><strong>Broader context:</strong> Part of a wider AI strategy pullback on Windows 11<br><strong>Copilot changes:</strong> Integrations in Notepad and Paint under review; new Copilot buttons paused<br><strong>Official statement:</strong> Windows president Pavan Davuluri told The Verge that 2026 will focus on performance, reliability, and "overall experience"</div></div><hr><p>The reassessment follows sustained user backlash against Microsoft's AI-first approach to Windows. Davuluri's November 2025 tweet describing Windows as an "agentic OS" drew thousands of negative replies. A problematic January 2026 update that caused boot failures, shutdown bugs, and cloud app crashes further eroded trust. Microsoft is not abandoning AI entirely: Semantic Search, Windows ML, Agentic Workspace, and developer-facing AI APIs continue, but the strategy is shifting toward background integration rather than visible UI features. The Recall concept may survive in a different form, but the brand appears damaged beyond repair.</p><p><strong>Sources:</strong> <a href="https://tech.slashdot.org/story/26/02/02/1826219/microsoft-weighs-retreat-from-windows-11-ai-push-reviews-copilot-integrations-and-recall?ref=docupoint.eu">Windows Central (via Slashdot)</a> · <a href="https://www.techradar.com/computing/windows/ill-believe-it-when-i-see-it-windows-11-users-are-cynical-about-microsofts-promises-to-fix-the-os-and-stop-pushing-ai?ref=docupoint.eu">TechRadar</a> · <a href="https://digiconasia.net/news/windows-11-ai-push-recoils-after-user-backlash?ref=docupoint.eu">DigiconAsia</a> · <a href="https://www.windowslatest.com/2026/01/31/microsoft-reportedly-admits-windows-11-went-off-track-cuts-back-copilot-and-promises-real-fixes-in-2026/?ref=docupoint.eu">Windows Latest</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[SharePoint eSignature Adds Drawn Signature Option]]></title>
                    <description><![CDATA[eSignature for Microsoft 365 adds drawn signature option for PDFs using stylus, touch, or mouse. Rolling out mid-March to mid-May 2026. No admin action required.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/sharepoint-esignature-adds-drawn-signature-option/</link>
                    <guid isPermaLink="false">6990f9d949431d0001e7421d</guid>

                        <category><![CDATA[Radar]]></category>
                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[SharePoint Online]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Fri, 30 Jan 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>eSignature for Microsoft 365 is adding a drawn signature option, letting signers use a stylus, touch, or mouse to draw their signature on PDFs. The feature rolls out worldwide from mid-March to mid-May 2026.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Rollout:</strong> Mid-March to mid-May 2026<br><strong>Input methods:</strong> Stylus, touch, or mouse<br><strong>Applies to:</strong> PDF signing via eSignature for Microsoft 365<br><strong>User choice:</strong> Signers can switch between drawn and typed signatures<br><strong>Action required:</strong> None. Enabled by default, no admin configuration needed</div></div><hr><p>This builds on earlier eSignature expansions: Word document support arrived in July 2025, and the service went globally available in late 2025. Drawn signatures give signers a more natural experience, particularly on touch-enabled devices. Organizations using eSignature for document workflows do not need to change any settings; the new option appears automatically alongside the existing typed signature.</p><p><strong>Sources:</strong> <a href="https://mc.merill.net/message/MC1225195?ref=docupoint.eu">MC1225195</a> · <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?id=548670&ref=docupoint.eu">Roadmap 548670</a> · <a href="https://m365admin.handsontek.net/drawn-electronic-signatures-esignature-microsoft-365/?ref=docupoint.eu">HandsOnTek</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Standalone SharePoint Online and OneDrive Plans Retiring by 2029]]></title>
                    <description><![CDATA[Microsoft retiring standalone SharePoint Online Plan 1/2 and OneDrive for Business Plan 1/2. Sales end June 2026, renewals end January 2027, full retirement December 2029.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/standalone-sharepoint-online-and-onedrive-plans-retiring-by-2029/</link>
                    <guid isPermaLink="false">6985b08edf8a9200018c4b92</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[OneDrive]]></category>
                        <category><![CDATA[licensing]]></category>
                        <category><![CDATA[retirement]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Thu, 29 Jan 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft is retiring standalone SharePoint Online and OneDrive for Business plans (Plan 1 and Plan 2), ending one of the more affordable entry points into its cloud ecosystem. Customers must transition to Microsoft 365 suites or alternative storage options.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>End of sale:</strong> June 1, 2026 (no new customers or tenants)<br><strong>End of renewals:</strong> January 2027 (existing contracts honored)<br><strong>Full retirement:</strong> December 2029 (all standalone plans cease)<br><strong>Affected plans:</strong> SPO Plan 1 ($5/user/month), SPO Plan 2 ($10/user/month), ODB Plan 1, ODB Plan 2<br><strong>Alternatives:</strong> Microsoft 365 Business/Enterprise suites, capacity packs, or pay-as-you-go storage</div></div><hr><p>Microsoft cites low customer demand, "unintended or nonstandard usage," and higher operational costs for maintaining these plans. Industry observers note the "nonstandard usage" likely refers to customers using standalone plans primarily for cheap, high-capacity cloud storage. For SMBs currently on Plan 1 at $5/user/month, migration to Microsoft 365 Business Basic ($6/user/month) represents the cheapest path forward, though larger organizations face more significant cost increases when moving to E3/E5 suites.</p><p><strong>Sources:</strong> <a href="https://pupuweb.com/mc1224567-retirement-of-sharepoint-online-and-onedrive-for-business-standalone-plans/?ref=docupoint.eu">MC1224567</a> · <a href="https://www.theregister.com/2026/02/03/microsoft_retires_sharepoint_onedrive_standalone/?ref=docupoint.eu">The Register</a> · <a href="https://petri.com/microsoft-retires-standalone-sharepoint-onedrive-plans/?ref=docupoint.eu">Petri</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Site Lifecycle Management Email Customization Now Generally Available]]></title>
                    <description><![CDATA[Email customization for Site Lifecycle Management policies is now GA. Admins can modify subject lines, message bodies, and guidance URLs for SLM notification emails. Requires SAM or Copilot license.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/site-lifecycle-management-email-customization-now-generally-available/</link>
                    <guid isPermaLink="false">6985b0a7df8a9200018c4ba7</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[governance]]></category>
                        <category><![CDATA[administration]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 28 Jan 2026 15:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Email customization for Site Lifecycle Management policies is now generally available in the SharePoint Admin Center. Admins can tailor notification emails sent to site owners across all SLM policy types.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Status:</strong> Generally available (January 28, 2026)<br><strong>Scope:</strong> All SLM policy types (inactive site, site ownership, site attestation)<br><strong>Customizable:</strong> Subject lines, message bodies, and guidance URLs<br><strong>Prerequisite:</strong> Custom domain email must be configured in Microsoft admin center<br><strong>License:</strong> SharePoint Advanced Management or Microsoft 365 Copilot</div></div><hr><p>Admins can modify emails for both new and existing policies via Edit configuration. If custom domain sending is not configured in the Microsoft admin center, a warning appears and customization is unavailable. Default emails from noreply@sharepoint.com continue to work if no customization is applied. No action is required for organizations satisfied with the default notification emails.</p><p><strong>Sources:</strong> <a href="https://mc.merill.net/message/MC1222976?ref=docupoint.eu">MC1222976</a> · <a href="https://learn.microsoft.com/en-us/sharepoint/site-lifecycle-management?ref=docupoint.eu">Microsoft Learn</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[SharePoint Maps Web Part Migrating from Bing Maps to Azure Maps]]></title>
                    <description><![CDATA[SharePoint Maps web part migrating from Bing Maps to Azure Maps starting March 2026. No opt-out. Functionality losses include business entity search, bird&#x27;s eye view, and street view.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/sharepoint-maps-web-part-migrating-from-bing-maps-to-azure-maps/</link>
                    <guid isPermaLink="false">6985b09adf8a9200018c4b9b</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[web parts]]></category>
                        <category><![CDATA[Azure Maps]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 28 Jan 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>The SharePoint Maps web part will migrate from Bing Maps to Azure Maps starting March 2026, completing by mid-April. The migration is automatic with no opt-out available. Several features will be removed.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Migration window:</strong> March 2026 to mid-April 2026<br><strong>Opt-out:</strong> None available<br><strong>Removed:</strong> Business entity search, bird's eye view, street view<br><strong>Limited:</strong> Autosuggestions for Chinese, Japanese, and Korean languages<br><strong>Action required:</strong> Update network allowlists and firewall rules for Azure Maps domains</div></div><hr><p>The web part will be renamed to reflect the Azure Maps branding. When bird's eye or street view is unavailable, the web part falls back to road view rather than showing an error. Site owners and admins using the Maps web part should test their pages after the migration completes and notify help desk personnel about the functionality changes.</p><p><strong>Sources:</strong> <a href="https://mc.merill.net/message/MC1222981?ref=docupoint.eu">MC1222981</a> · <a href="https://www.directionsonmicrosoft.com/in-brief/sharepoint-maps-web-part-to-move-to-azure-maps/?ref=docupoint.eu">Directions on Microsoft</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[SSRS Report Viewer SharePoint Web Part Losing Support April 2026]]></title>
                    <description><![CDATA[Support for the SSRS Report Viewer SharePoint web part ends April 13, 2026. Web part remains functional but unsupported. Transition to URL parameter embedding recommended.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/ssrs-report-viewer-sharepoint-web-part-losing-support-april-2026/</link>
                    <guid isPermaLink="false">6985b0b6df8a9200018c4bb2</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[SSRS]]></category>
                        <category><![CDATA[reporting]]></category>
                        <category><![CDATA[retirement]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 28 Jan 2026 11:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Support for the SQL Server Reporting Services (SSRS) Report Viewer SharePoint web part ends on April 13, 2026. The web part will remain functional but will no longer receive updates or support.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>End of support:</strong> April 13, 2026<br><strong>Impact:</strong> No more updates or patches after deadline<br><strong>Web part status:</strong> Remains functional but unsupported<br><strong>Alternative:</strong> Embed SSRS reports using URL parameters (`rs:Embed=true`)<br><strong>Affected environments:</strong> SharePoint Server 2013, 2016, and 2019 with SSRS integration</div></div><hr><p>Microsoft recommends transitioning to the URL parameter approach for embedding reports in SharePoint pages. This method uses the <code>rs:Embed=true</code> parameter and works with both classic and modern SharePoint pages via the Embed web part. Organizations relying on the Report Viewer web part for paginated report display should plan their transition before the support deadline.</p><p><strong>Sources:</strong> <a href="https://learn.microsoft.com/en-us/sql/reporting-services/report-server-sharepoint/deploy-report-viewer-web-part?ref=docupoint.eu">Microsoft Learn</a> · <a href="https://m365admin.handsontek.net/power-bi-end-support-prem-sharepoint-web-part/?ref=docupoint.eu">M365 Admin</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Microsoft Recall: The Privacy Nightmare That Won&#x27;t Die]]></title>
                    <description><![CDATA[Microsoft&#x27;s controversial AI feature that screenshots everything you do is now rolling out to Windows 11 users. Security researchers warn that reactivation pathways and update cycles may undermine its &quot;opt-in&quot; promise.]]></description>
                    <link>https://www.docupoint.eu/blog/microsoft-recall-still-a-thing/</link>
                    <guid isPermaLink="false">6947129c8b04f00001d939d8</guid>

                        <category><![CDATA[Global Digital Sovereignty]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[microsoft]]></category>
                        <category><![CDATA[Windows]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[AI]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 28 Jan 2026 08:00:17 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Microsoft-Recall---still-a-thing-1.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Microsoft-Recall---still-a-thing-1.png" alt="Microsoft Recall: The Privacy Nightmare That Won&#x27;t Die"/> <p>In May 2025, <a href="https://signal.org/?ref=docupoint.eu">Signal</a> did something remarkable. The encrypted messaging app, trusted by journalists, activists, and security professionals worldwide, rolled out a feature called "Screen security" for its Windows desktop application. The purpose: to block Microsoft Recall from capturing Signal conversations.</p><p>Signal's engineering team <a href="https://windowsforum.com/threads/microsoft-recall-on-windows-11-privacy-concerns-signals-countermeasure-future-implications.367802/?ref=docupoint.eu">explicitly stated</a> they do not trust Microsoft's safeguards to be effective. When the maker of one of the world's most secure messaging apps builds defenses specifically against your AI feature, that says something.</p><p>Two months later, <a href="https://brave.com/privacy-updates/35-block-recall/?ref=docupoint.eu">Brave browser</a> and <a href="https://www.ghacks.net/2025/07/28/adguard-will-also-block-windows-recall-to-protect-users/?ref=docupoint.eu">AdGuard</a> followed suit. The same month, Penn's Office of Information Security <a href="https://isc.upenn.edu/news/warnings-microsofts-recall-tool-4142025?ref=docupoint.eu">issued a warning</a> to its community: "Recall introduces substantial and unacceptable security, legality, and privacy challenges."</p><hr><p><strong>The pattern is now undeniable.</strong> Microsoft Recall, the AI feature that <a href="https://learn.microsoft.com/en-us/windows/ai/recall/?ref=docupoint.eu">takes screenshots of everything you do</a> on your computer every few seconds, has returned. After being <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-delays-windows-recall-amid-privacy-and-security-concerns/?ref=docupoint.eu">pulled in June 2024</a> following public backlash, it reappeared in the <a href="https://nguard.com/sa-microsofts-recall-saga-continuous-coverage-and-latest-news/?ref=docupoint.eu">Windows 11 24H2 update</a> in April-May 2025.</p><p>Microsoft insists Recall is opt-in. But security researchers have identified troubling reactivation pathways: once enabled even once, <a href="https://www.kaspersky.com/blog/recall-2025-risks-benefits/53407/?ref=docupoint.eu">Recall can be reactivated by anyone who knows the device PIN</a>, no biometric authentication required. And Windows updates have a <a href="https://proton.me/blog/disable-windows-recall?ref=docupoint.eu">documented history of resetting privacy settings</a> without warning.</p><p>The question is no longer whether Recall poses a privacy risk. The question is why Microsoft keeps pushing it.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/REcall-timeline.jpg" class="kg-image" alt="Microsoft Recall Timeline from June 2024 to July 2025" loading="lazy" width="2000" height="520" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/REcall-timeline.jpg 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/REcall-timeline.jpg 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1600/2026/01/REcall-timeline.jpg 1600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/REcall-timeline.jpg 2000w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Timeline of Microsoft Recall: From announcement to industry pushback</span></figcaption></figure><hr><h2 id="what-recall-actually-does">What Recall actually does</h2><p>Microsoft Recall <a href="https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c?ref=docupoint.eu">continuously captures screenshots</a> of your screen activity every few seconds. It then uses AI and optical character recognition to make everything searchable, creating a complete timeline of your digital life.</p><p>Every email you read. Every document you work on. Every website you visit. Every private conversation in Teams or WhatsApp. Every password you type. Every bank statement you view.</p><p>All of it. Captured. Stored. Indexed.</p><p>Microsoft positions this as a productivity feature, allowing you to "retrace your steps." But the implications extend far beyond convenience.</p><h3 id="the-security-failures">The security failures</h3><p>Independent testing by <a href="https://www.techtarget.com/searchenterpriseai/feature/Privacy-and-security-risks-surrounding-Microsoft-Recall?ref=docupoint.eu">TechTarget</a> and <a href="https://www.kaspersky.com/blog/recall-2025-risks-benefits/53407/?ref=docupoint.eu">Kaspersky</a> has revealed that Recall's "Filter sensitive information" feature still misses critical data:</p><ul><li>Credit card numbers</li><li>Bank account balances</li><li>Social Security numbers</li><li>Passwords</li></ul><p>According to <a href="https://www.techrepublic.com/article/news-microsoft-recall-expands-rollout/?ref=docupoint.eu">Ars Technica</a>, some users have reported instances of credit card numbers, cheques, and emails with personal data being captured despite the filter. The sensitive information filter is not reliable. Users who trust it are exposed.</p><h3 id="the-third-party-problem">The third-party problem</h3><p>Recall does not just capture your data. It captures other people's information too. WhatsApp conversations with contacts. Client documents under NDA. Confidential emails from colleagues.</p><p>The third parties whose data is captured <a href="https://windowsforum.com/threads/microsoft-windows-11-recall-feature-privacy-risks-impact-on-users.366106/?ref=docupoint.eu">never consented</a> to being recorded. In enterprise environments, this creates significant legal exposure under GDPR, HIPAA, and PCI DSS.</p><p>Even worse: if a self-destructing WhatsApp or Signal chat is open on screen, <a href="https://www.kaspersky.com/blog/recall-2025-risks-benefits/53407/?ref=docupoint.eu">Recall will save it anyway</a>, despite the chat's privacy policies. Photos and videos intended for one-time viewing will be stored if just one person in the conversation uses Recall.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260104191718.png" class="kg-image" alt="Microsoft Recall data capture visualization" loading="lazy" width="1206" height="658" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260104191718.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260104191718.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260104191718.png 1206w" sizes="(min-width: 720px) 720px"></figure><hr><h2 id="the-troubled-history">The troubled history</h2><p>The story of Microsoft Recall is one of repeated controversy, withdrawal, and return. For the complete timeline with detailed coverage of each event, see our <a href="https://www.docupoint.eu/microsoft-recall/">Microsoft Recall Timeline</a>.</p><p><strong>June 2024</strong>: Microsoft announced Recall with screenshots stored unencrypted in plaintext, enabled by default, impossible to remove. The UK ICO launched inquiries. Days later, Microsoft <a href="https://www.docupoint.eu/microsoft-recall/microsoft-pulls-recall-after-security-backlash/">pulled the feature entirely</a>.</p><p><strong>September 2024</strong>: Microsoft <a href="https://www.docupoint.eu/microsoft-recall/microsoft-announces-recall-security-overhaul/">announced a security overhaul</a>: encryption, biometric authentication, and opt-in activation.</p><p><strong>April 2025</strong>: Recall <a href="https://www.docupoint.eu/microsoft-recall/recall-returns-for-windows-insiders/">returned for Windows Insiders</a> with security updates in place.</p><p><strong>May 2025</strong>: <a href="https://www.docupoint.eu/microsoft-recall/recall-rolls-out-to-public-signal-announces-countermeasure/">Public rollout</a> to all Copilot+ PC users. Signal immediately released its "Screen security" countermeasure.</p><p><strong>July 2025</strong>: <a href="https://www.docupoint.eu/microsoft-recall/brave-and-adguard-block-recall-by-default/">Brave and AdGuard</a> announced they would block Recall by default. The same week, Microsoft introduced <a href="https://www.docupoint.eu/microsoft-recall/microsoft-announces-copilot-vision-recall-goes-to-the-cloud/">Copilot Vision</a>, sending screenshots to Microsoft's cloud servers, deliberately excluded from the EU.</p><p><strong>October 2025</strong>: <a href="https://www.docupoint.eu/microsoft-recall/gaming-copilot-controversy-screenshot-capture-without-clear-consent/">Gaming Copilot controversy</a>: users discovered screenshot capture without clear consent, installed automatically through Xbox Game Bar.</p><hr><h2 id="the-opt-in-problem">The "opt-in" problem</h2><p>Microsoft's <a href="https://support.microsoft.com/en-us/windows/privacy-and-control-over-your-recall-experience-d404f672-7647-41e5-886c-a3c59680af15?ref=docupoint.eu">official documentation</a> states clearly: "Snapshots are not taken or saved unless you choose to use Recall."</p><p>But security researchers have identified significant gaps in this "opt-in" promise.</p><h3 id="reactivation-without-biometrics">Reactivation without biometrics</h3><p><a href="https://www.kaspersky.com/blog/recall-2025-risks-benefits/53407/?ref=docupoint.eu">Kaspersky's analysis</a> found that once Recall has been enabled even once, it can be reactivated by anyone who knows the device PIN, no biometric authentication required. A family member, coworker, or anyone with temporary access to your unlocked computer can turn Recall back on.</p><h3 id="settings-reset-after-updates">Settings reset after updates</h3><p><a href="https://proton.me/blog/disable-windows-recall?ref=docupoint.eu">Proton's research</a> warns: "Windows updates have a history of reversing privacy settings without warning." Users who disabled Recall may find it quietly reactivated after the next update cycle. There is no way to monitor if Recall gets turned back on automatically.</p><h3 id="low-bar-for-reactivation">Low bar for reactivation</h3><p><a href="https://windowsforum.com/threads/microsoft-windows-11-recall-feature-privacy-risks-impact-on-users.366106/?ref=docupoint.eu">Windows Forum analysis</a> notes that Microsoft made this feature "opt-in during installation, but with a low security bar for reactivation if it's ever been enabled. After initial consent, it becomes much easier to re-enable with minimal user interaction."</p><h3 id="workplace-pressure">Workplace pressure</h3><p>In enterprise environments, IT administrators can <a href="https://learn.microsoft.com/en-us/windows/client-management/manage-recall?ref=docupoint.eu">enable Recall at the system level</a>. While Microsoft requires end users to activate it on their individual computers, the reality of workplace dynamics means consent may not be truly voluntary. Employees can feel pressured to enable features pushed by their employer.</p><p>This raises fundamental questions about informed versus coerced consent.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/recall-3.jpg" class="kg-image" alt="The gap between Microsoft's opt-in promise and reality" loading="lazy" width="1856" height="576" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/recall-3.jpg 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/recall-3.jpg 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1600/2026/01/recall-3.jpg 1600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/recall-3.jpg 1856w" sizes="(min-width: 720px) 720px"></figure><hr><h2 id="institutional-and-industry-response">Institutional and industry response</h2><h3 id="penns-security-office">Penn's security office</h3><p>Penn's Office of Information Security <a href="https://isc.upenn.edu/news/warnings-microsofts-recall-tool-4142025?ref=docupoint.eu">reviewed Recall in April 2025</a> and issued an unambiguous conclusion:</p><blockquote>"Recall introduces substantial and unacceptable security, legality, and privacy challenges."</blockquote><p>Penn is not a small organization with limited IT resources. It is a major research university with extensive security expertise. When institutions of this caliber reject a feature as "unacceptable," it carries weight.</p><h3 id="signals-active-defense-may-2025">Signal's active defense (May 2025)</h3><p>Signal's response was more than a warning. It was a technical countermeasure.</p><p>In May 2025, Signal <a href="https://windowsforum.com/threads/microsoft-recall-on-windows-11-privacy-concerns-signals-countermeasure-future-implications.367802/?ref=docupoint.eu">announced "Screen security"</a> for its Windows desktop application. The feature uses DRM techniques to render screen capture attempts as black rectangles. It is enabled by default for all Windows 11 users running Signal desktop.</p><p>Signal explicitly stated they do not trust that Microsoft's safeguards can be universally effective now or in the future. The trade-off: Signal's approach also blocks legitimate screenshots, including those needed by accessibility software like screen readers.</p><h3 id="brave-and-adguard-join-the-resistance-july-2025">Brave and AdGuard join the resistance (July 2025)</h3><p>Two months after Signal, both <a href="https://brave.com/privacy-updates/35-block-recall/?ref=docupoint.eu">Brave browser</a> and <a href="https://www.ghacks.net/2025/07/28/adguard-will-also-block-windows-recall-to-protect-users/?ref=docupoint.eu">AdGuard</a> announced they would block Recall by default.</p><p>Brave's approach is more surgical than Signal's. The browser marks every tab as "private" to the operating system, preventing Recall capture while maintaining normal screenshot functionality for accessibility tools. As Brave noted: "We think it's vital that your browsing activity on Brave does not accidentally end up in a persistent database, which is especially ripe for abuse in highly-privacy-sensitive cases such as intimate partner violence."</p><p>AdGuard's implementation goes further: it blocks Recall system-wide across all applications, not just within one app.</p><p>When three of the most privacy-focused software makers in the industry (Signal, Brave, and AdGuard) all build countermeasures against the same Microsoft feature, the message is clear.</p><h3 id="regulatory-scrutiny">Regulatory scrutiny</h3><p>The UK Information Commissioner's Office <a href="https://nguard.com/sa-microsofts-recall-saga-continuous-coverage-and-latest-news/?ref=docupoint.eu">launched inquiries</a> in May 2024. EU regulators are watching. GDPR compliance remains in question, particularly around:</p><ul><li>Consent mechanisms for third-party data capture</li><li>The "legitimate interest" basis for continuous surveillance</li><li>Data minimization requirements</li></ul><p>For organizations operating in regulated industries, Recall may create compliance exposure that no productivity benefit can justify.</p><hr><h2 id="protecting-yourself">Protecting yourself</h2><h3 id="check-if-recall-is-running">Check if Recall is running</h3><p>Open Task Manager (Ctrl+Shift+Esc) and look for "Recall" in the processes list. If you see "Recall (preview)" running and you never enabled it, investigate immediately.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20251208104358.png" class="kg-image" alt="Windows Task Manager showing Recall process" loading="lazy" width="1225" height="154" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20251208104358.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20251208104358.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20251208104358.png 1225w" sizes="(min-width: 720px) 720px"></figure><h3 id="disable-recall-basic">Disable Recall (basic)</h3><ol><li>Press Windows+i to open Settings</li><li>Click "Privacy &amp; security" in the left sidebar</li><li>Navigate to "Recall &amp; snapshots"</li><li>Turn it off</li></ol><h3 id="disable-recall-permanent">Disable Recall (permanent)</h3><p>For a more permanent solution, according to <a href="https://proton.me/blog/disable-windows-recall?ref=docupoint.eu">Proton's guide</a>:</p><ol><li>Search "Turn Windows features on or off" in the taskbar</li><li>Uncheck "Recall"</li><li>Restart your computer</li></ol><p>This removes Recall from the system entirely, rather than just disabling it.</p><h3 id="enterprise-use-group-policy">Enterprise: use Group Policy</h3><p>IT administrators can <a href="https://learn.microsoft.com/en-us/windows/client-management/manage-recall?ref=docupoint.eu">disable Recall via Group Policy</a>:</p><ol><li>Disable Group Policy: "Allow Recall to be enabled"</li><li>Restart PCs</li><li>This completely removes the Recall toggle and related components</li></ol><h3 id="use-privacy-focused-software">Use privacy-focused software</h3><p>Consider switching to browsers and apps that block Recall:</p><ul><li><strong>Brave browser</strong> (v1.81+): Blocks Recall by default while preserving normal screenshot functionality</li><li><strong>Signal desktop</strong>: Blocks all screenshots including Recall</li><li><strong>AdGuard</strong>: System-wide Recall blocking</li></ul><h3 id="check-after-every-update">Check after every update</h3><p>This is the most important step: verify Recall is still off after each Windows Update. Microsoft's update process has a documented history of resetting privacy settings without warning.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260104192313.png" class="kg-image" alt="Protection steps checklist for Microsoft Recall" loading="lazy" width="1214" height="372" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260104192313.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260104192313.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260104192313.png 1214w" sizes="(min-width: 720px) 720px"></figure><hr><h2 id="the-bigger-picture">The bigger picture</h2><p>Recall represents a fundamental shift in how Microsoft views your computer. It is no longer just a tool you use. It is a platform that Microsoft believes should record everything you do "for your convenience."</p><h3 id="the-pattern-continues">The pattern continues</h3><p>In July 2025, Microsoft introduced <a href="https://www.theregister.com/2025/07/23/microsoft_copilot_vision/?ref=docupoint.eu">Copilot Vision</a>, an extension of Recall that takes data collection even further. While Recall processes screenshots locally, Copilot Vision sends them to Microsoft's cloud servers for analysis. Microsoft deliberately excluded Copilot Vision from the European Union, a tacit acknowledgment that its cloud-based model cannot comply with GDPR.</p><p>In October 2025, <a href="https://winbuzzer.com/2025/10/26/microsoft-defends-gaming-copilot-privacy-after-backlash-over-hidden-screenshot-data-capturing-xcxwbn/?ref=docupoint.eu">Gaming Copilot</a> sparked another privacy controversy when users discovered it was capturing gameplay screenshots and sending data to Microsoft servers by default, installed automatically through Xbox Game Bar without clear consent.</p><p>When you combine these developments:</p><ul><li>Recall's continuous local screenshots</li><li>Copilot Vision's cloud-based screen analysis</li><li>Gaming Copilot's default-on screenshot capture</li><li>Windows 11's mandatory telemetry</li></ul><p>A pattern emerges. Microsoft wants your data. All of it. And they are making it increasingly difficult to say no.</p><hr><p>Signal, Brave, and AdGuard didn't build Recall countermeasures as a marketing stunt. They built them because their security teams concluded that Microsoft Recall poses a genuine risk to user privacy, and that Microsoft's safeguards cannot be fully trusted.</p><p>Penn's Office of Information Security reviewed Recall and found it "unacceptable." The UK Information Commissioner's Office is investigating. Independent testing shows the sensitive information filter fails to catch passwords and financial data. Security researchers have documented reactivation pathways that undermine the "opt-in" promise.</p><p>Yet Microsoft continues to expand its screen-capture ecosystem. Recall locally. Copilot Vision in the cloud. Gaming Copilot by default.</p><p>The market has spoken: Copilot+ PCs made up <a href="https://proton.me/blog/disable-windows-recall?ref=docupoint.eu">less than 2% of Windows laptops sold</a> in early 2025. Users are not embracing Microsoft's vision of an AI that watches everything they do.</p><p>Check your Task Manager. Disable Recall if you find it. Switch to privacy-respecting browsers. Keep checking after every update. Because in 2025, your Windows PC may be watching everything you do, and the "opt-in" promise may be thinner than Microsoft suggests.</p><h3 id="timeline">Timeline</h3><ul><li><a href="https://www.docupoint.eu/microsoft-recall/">Microsoft Recall Timeline - DocuPoint</a></li></ul>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[1984 → 2048: The Fourth Way]]></title>
                    <description><![CDATA[Unlike Winston Smith, Europe has what Orwell&#x27;s protagonist never did: democratic institutions, regulatory power, and 450 million citizens who can still choose. This article examines whether a fourth way between the superstates is possible.]]></description>
                    <link>https://www.docupoint.eu/blog/1984-2048-the-fourth-way/</link>
                    <guid isPermaLink="false">695d826105158200010a509c</guid>

                        <category><![CDATA[Digital Trust Wars]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[chat-control]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 26 Jan 2026 08:00:07 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221045.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221045.png" alt="1984 → 2048: The Fourth Way"/> <p><em>Part 3 of 3 in the "1984 → 2048: Europe's Choice" trilogy</em></p><p>Denmark's Justice Minister stood at a podium in Copenhagen and said the quiet part out loud:</p><blockquote><strong>"We must break with the totally erroneous perception that it is everyone's civil liberty to communicate on encrypted messaging services."</strong></blockquote><p>Read that again. A sitting European minister, not Chinese, not Russian, <em>European</em>, declared that private communication is not a fundamental right.</p><p>This is not the warning. This is the event the warning was about.</p><p>In 1984, O'Brien is the Inner Party member who tortures Winston into loving Big Brother. He doesn't hide what the Party is. He explains it: <em>"We are not interested in the good of others; we are interested solely in power."</em></p><p>Peter Hummelgaard is Europe's O'Brien. And unlike Orwell's fiction, he's real, he's in power, and he's telling you exactly what he intends to do.</p><p>In <a href="https://www.docupoint.eu/1984-2048-three-digital-superstates/">Part 1</a>, we mapped the three digital superstates. In <a href="https://www.docupoint.eu/1984-2048-europe-under-siege/">Part 2</a>, we documented how Europe is being besieged. Now comes the question that matters: <strong>Is there a fourth way, or will Europe become the thing it claims to oppose?</strong></p><p>Europe possesses something Winston Smith never had: democratic institutions that still function, regulatory power that still bites, and 450 million citizens who can still choose. The question is not whether resistance is possible. The question is whether Europe will use what it has, or whether it will build the surveillance state itself.</p><p>The clock is striking thirteen. The hour is not yet lost. But the chimes are coming from inside the house.</p><hr><h2 id="europes-resistance-what-winston-couldnt-have">Europe's resistance: what Winston couldn't have</h2><p>In 1984, there is no resistance. The Brotherhood turns out to be a Party fiction. Emmanuel Goldstein may not exist. The proles are kept too ignorant and entertained to revolt. Hope is an illusion the Party manufactures to identify dissidents.</p><p><strong>Europe in 2026 is not Oceania. Not yet.</strong></p><h3 id="what-winston-smith-couldnt-have">What Winston Smith couldn't have</h3><p>Winston had nothing. Europe has everything it needs, if it chooses to use it.</p><h4 id="democratic-institutions-flawed-but-real">Democratic institutions: flawed but real</h4><p>Winston lived under a one-party state where elections were theater and courts were instruments of terror. Europeans live under democracies where governments can be voted out, where courts can strike down surveillance laws as the <a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2014-04/cp140054en.pdf?ref=docupoint.eu">ECJ did with the Data Retention Directive</a>. Citizens can sue corporations and win, as <a href="https://noyb.eu/en/project/schrems-vs-facebook?ref=docupoint.eu">Max Schrems did against Facebook</a>, twice. Regulators can impose billion-euro fines, as with <a href="https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fine-facebook-result-edpb-binding-decision_en?ref=docupoint.eu">Meta's €1.2 billion GDPR penalty</a> in 2023.</p><p>These institutions are imperfect. They are slow. They are sometimes captured by the interests they should regulate. But they exist, and that existence is the difference between 1984 and 2026.</p><h4 id="regulatory-power-the-brussels-effect">Regulatory power: the Brussels Effect</h4><p>Europe has something no other bloc possesses: the power to set global standards through market access. The "<a href="https://www.cambridge.org/core/books/brussels-effect/DC04DEB2ED4D068D27F20B58B25E5263?ref=docupoint.eu">Brussels Effect</a>" means that companies wanting access to 450 million consumers must comply with European rules, and often apply those rules globally rather than maintain separate systems.</p><p>This power has already reshaped the digital world. The <a href="https://gdpr.eu/?ref=docupoint.eu">GDPR</a> of 2018 forced global privacy policies to improve; California's CCPA and Brazil's LGPD follow its model. The <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-services-act-package?ref=docupoint.eu">Digital Services Act</a> of 2024 requires platforms to address illegal content, algorithmic transparency, and researcher access. The <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=docupoint.eu">AI Act</a>, also 2024, became the world's first comprehensive AI regulation, banning social scoring, restricting facial recognition, and requiring transparency for high-risk systems. The <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-markets-act?ref=docupoint.eu">Digital Markets Act</a> forces Big Tech "gatekeepers" to open their platforms, allow interoperability, and stop self-preferencing.</p><p>The superstates can lobby against these regulations. They can threaten retaliation. They can delay compliance. But they cannot ignore a €17 trillion market. <strong>Europe's regulatory power is sovereignty in action.</strong></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221219.png" class="kg-image" alt="The Brussels Effect" loading="lazy" width="1234" height="757" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106221219.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106221219.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221219.png 1234w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Brussels Effect: Europe's regulatory power as defense</span></figcaption></figure><h4 id="450-million-people-%E2%82%AC17-trillion-economy">450 million people, €17 trillion economy</h4><p>Winston was alone. Europe is not.</p><p>The European Union represents 450 million people, larger than the United States. Its €17 trillion GDP makes it the world's third-largest economy. A market large enough to set global standards, if it chooses to, with unified regulations, free movement, and a shared currency for most members.</p><p>This is not a small nation that can be bullied into compliance. This is a bloc that can, if it chooses, build its own infrastructure, set its own standards, and chart its own course. The question is not capability. It is will.</p><h3 id="citizens-are-waking-up">Citizens are waking up</h3><p>In 1984, Winston writes: "If there is hope, it lies in the proles." But the proles never organize. European citizens already have.</p><h4 id="privacy-as-a-value-not-just-regulation">Privacy as a value, not just regulation</h4><p>GDPR did not emerge from bureaucratic void. It emerged from <a href="https://edri.org/?ref=docupoint.eu">decades of European privacy activism</a>, from the memory of surveillance states both Nazi and Communist, from a cultural understanding that privacy is not "having something to hide" but having the right to a self that is not observed, measured, and monetized.</p><p>Recent surveys show this consciousness growing. <a href="https://www.computerweekly.com/news/366633894/European-governments-opt-for-open-source-alternatives-to-Big-Tech-encrypted-communications?ref=docupoint.eu">45% of European organizations</a> increased their interest in digital sovereignty solutions between 2024 and 2025. <a href="https://www.computerworld.com/article/4064116/a-european-alternative-to-m365-nextcloud-looks-to-capitalize-on-digital-sovereignty-interest.html?ref=docupoint.eu">Nextcloud reports a threefold increase</a> in requests for sovereign cloud alternatives.</p><h4 id="open-source-as-resistance">Open source as resistance</h4><p>The Party controlled all technology. Europeans can build their own.</p><p><a href="https://kitemetric.com/blogs/top-10-european-open-source-projects-to-watch-in-2025?ref=docupoint.eu">European open source projects</a> are creating alternatives to every major American platform. <a href="https://nextcloud.com/?ref=docupoint.eu">Nextcloud</a> in Germany offers self-hosted cloud storage, collaboration, and office suite capabilities, now used by the German federal government, French ministry of education, and thousands of European organizations. <a href="https://matrix.org/?ref=docupoint.eu">Matrix</a> provides a decentralized, encrypted messaging protocol adopted by the <a href="https://element.io/case-studies/tchap?ref=docupoint.eu">French government</a>, German armed forces, and NATO for secure communications. <a href="https://joinpeertube.org/?ref=docupoint.eu">PeerTube</a> from France offers federated video hosting with no tracking, no ads, and no algorithmic manipulation. <a href="https://joinmastodon.org/?ref=docupoint.eu">Mastodon</a>, also German, provides a decentralized social network where federated servers mean no single point of control or failure.</p><p>These are not toys. They are production-ready alternatives used by governments and enterprises. They prove that sovereignty is technically possible. The only question is adoption.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221517.png" class="kg-image" alt="European Alternatives Exist" loading="lazy" width="1162" height="727" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106221517.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106221517.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106221517.png 1162w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">European Alternatives Exist: The tools for digital sovereignty are ready</span></figcaption></figure><h4 id="citizens-demanding-change">Citizens demanding change</h4><p>The Party suppressed all dissent. European civil society fights back.</p><p><a href="https://edri.org/?ref=docupoint.eu">European Digital Rights (EDRi)</a> coordinates a network of 44 NGOs defending digital rights across Europe. <a href="https://www.laquadraturedunet.org/en/?ref=docupoint.eu">La Quadrature du Net</a> in France <a href="https://edri.org/our-work/how-to-fight-biometric-mass-surveillance-after-the-ai-act-a-legal-and-practical-guide/?ref=docupoint.eu">successfully sued</a> to stop algorithmic video surveillance in Grenoble. <a href="https://noyb.eu/?ref=docupoint.eu">noyb (None of Your Business)</a>, Max Schrems' organization, has filed hundreds of GDPR complaints, winning landmark cases against Facebook, Google, and Amazon.</p><p>The proles in 1984 never organized. European citizens already have.</p><hr><h2 id="the-clock-strikes-thirteen">The clock strikes thirteen</h2><p>The opening line of 1984: <em>"It was a bright cold day in April, and the clocks were striking thirteen."</em></p><p>The impossible time signals that something is fundamentally wrong. The world looks normal (bright, cold, April) but the clocks tell a truth that conscious minds have learned to ignore.</p><p><strong>In 2026, the clocks are striking thirteen. Most Europeans don't notice.</strong></p><h3 id="warning-signs-were-ignoring">Warning signs we're ignoring</h3><h4 id="facial-recognition-banned-in-theory-spreading-in-practice">Facial recognition: banned in theory, spreading in practice</h4><p>The AI Act <a href="https://www.europarl.europa.eu/news/en/press-room/20240308IPR19015/artificial-intelligence-act-meps-adopt-landmark-law?ref=docupoint.eu">prohibits live facial recognition in public spaces</a> from February 2025. But the exceptions swallow the rule: law enforcement can use it for victims, terrorists, and serious crime suspects. <a href="https://edri.org/our-work/how-to-fight-biometric-mass-surveillance-after-the-ai-act-a-legal-and-practical-guide/?ref=docupoint.eu">Critics warn</a> these exceptions are "very vague." Diego Naranjo of European Digital Rights calls it "the normalisation of mass surveillance."</p><h4 id="nothing-to-hide-as-accepted-truth">"Nothing to hide" as accepted truth</h4><p>The Party's greatest victory was making citizens police themselves. The modern equivalent: "If you have nothing to hide, you have nothing to fear."</p><p>This inverts the presumption of innocence. It assumes surveillance is neutral, that only the guilty need privacy, that watchers never abuse power.</p><p>History screams otherwise. The <a href="https://www.bstu.de/en/?ref=docupoint.eu">Stasi files</a> showed how "ordinary" surveillance destroyed lives. The <a href="https://www.theguardian.com/world/2013/aug/24/nsa-analysts-abused-surveillance-systems?ref=docupoint.eu">NSA's LOVEINT</a> scandal revealed analysts spying on love interests.</p><h4 id="chat-control-the-test-case">Chat Control: the test case</h4><p>We opened this article with Hummelgaard's declaration. Now consider what it means in practice.</p><p>The <a href="https://edri.org/our-work/chat-control-what-is-actually-going-on/?ref=docupoint.eu">Chat Control proposal</a> would mandate scanning of all private digital communications, including encrypted messages. The technical mechanism, "client-side scanning," would require messaging apps like Signal, WhatsApp, and Telegram to scan content <em>before</em> encryption, effectively <a href="https://www.eff.org/deeplinks/2025/12/after-years-controversy-eus-chat-control-nears-its-final-hurdle-what-know?ref=docupoint.eu">creating a backdoor into every private conversation</a>.</p><p>The <a href="https://www.eff.org/deeplinks/2025/09/chat-control-back-menu-eu-it-still-must-be-stopped-0?ref=docupoint.eu">Signal Foundation threatened to leave the EU market</a> rather than comply. Intelligence agencies warned against it. The UN emphasized that undermining encryption would breach privacy rights.</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr><th>Superstate</th><th>Justification</th><th>Method</th></tr>
</thead>
<tbody>
<tr><td><strong>China</strong></td><td>"Social stability"</td><td>Great Firewall, mandatory backdoors</td></tr>
<tr><td><strong>Russia</strong></td><td>"National security"</td><td>RuNet, SORM surveillance</td></tr>
<tr><td><strong>USA</strong></td><td>"Fighting terrorism"</td><td>PRISM, Section 702, CLOUD Act</td></tr>
<tr><td><strong>EU (Chat Control)</strong></td><td>"Protecting children"</td><td>Client-side scanning, encryption backdoors</td></tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>The justification changes. The surveillance is identical.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222612.png" class="kg-image" alt="Same Surveillance, Different Flags" loading="lazy" width="1194" height="688" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106222612.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106222612.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222612.png 1194w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Same Surveillance, Different Flags: Different justifications, identical methods</span></figcaption></figure><p><a href="https://eutechloop.com/return-of-chat-control/?ref=docupoint.eu">Germany ultimately voted against</a>. <a href="https://dig.watch/updates/denmark-drops-chat-control-proposal-amid-backlash?ref=docupoint.eu">Public pressure forced Denmark to drop mandatory scanning</a> in late 2025. But the proposal continues toward <a href="https://www.eff.org/deeplinks/2025/12/after-years-controversy-eus-chat-control-nears-its-final-hurdle-what-know?ref=docupoint.eu">final negotiations</a> with "voluntary" scanning requirements that critics warn will become mandatory.</p><p>The fourth way cannot be built on surveillance. The moment Europe breaks encryption "for the children," it loses the moral authority to criticize America for breaking it "for terrorism" or China for breaking it "for stability." Privacy is not divisible. Backdoors are backdoors. Once built, they will be exploited.</p><h3 id="what-happens-if-europe-fails">What happens if Europe fails</h3><p>Forget 2084. What does 2030 look like if Chat Control passes?</p><ul><li>Every photo you send is scanned before encryption</li><li>Every message is analyzed by AI that flags "suspicious" content</li><li>Your encrypted conversation with your lawyer? Not encrypted anymore</li><li>Signal leaves the EU market; you use whatever compromised app remains</li><li>The infrastructure exists, and the next government, or the one after that, will find new reasons to use it</li></ul><p>Once built, surveillance infrastructure doesn't get dismantled. It gets expanded. It gets normalized.</p><p><strong>The path to absorption runs through the next five years.</strong></p><hr><p>The final line of 1984: <em>"He loved Big Brother."</em></p><p>Winston Smith's defeat was total, not because the Party broke his body, but because it conquered his mind.</p><p><strong>Orwell imagined totalitarianism would require torture. The platforms discovered it only requires dopamine.</strong></p><p>"We needed to sort of give you a little dopamine hit every once in a while," <a href="https://www.axios.com/2017/11/09/sean-parker-unloads-on-facebook-god-only-knows-what-its-doing-to-our-childrens-brains?ref=docupoint.eu">confessed Sean Parker</a>, Facebook's founding president. "It's a social validation feedback loop... exploiting a vulnerability in human psychology."</p><p>The Party used pain. The platforms use pleasure. The algorithm <a href="https://journals.sagepub.com/doi/10.1177/17579139251331914?ref=docupoint.eu">hijacks reward circuits</a> with variable rewards, the same mechanism that makes slot machines addictive. Every notification is a pull of the lever.</p><p>The Party had to build a surveillance state. We crowdfunded ours through app purchases.</p><p>Big Brother doesn't need a telescreen on your wall. You bought one, put it in your pocket, and check it 150 times a day.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222359.png" class="kg-image" alt="The Dopamine Prison" loading="lazy" width="1222" height="726" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106222359.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106222359.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222359.png 1222w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Dopamine Prison: Comfortable captivity through digital addiction</span></figcaption></figure><p><strong>The superstates didn't conquer Europe's minds through invasion. They're doing it one dopamine hit at a time.</strong></p><hr><h2 id="what-you-can-do">What you can do</h2><p>Winston Smith had no options. You do.</p><h3 id="switch-your-tools">Switch your tools:</h3><ul><li>Email: <a href="https://proton.me/?ref=docupoint.eu">ProtonMail</a> or <a href="https://tuta.com/?ref=docupoint.eu">Tuta</a> (European, encrypted)</li><li>Cloud storage: <a href="https://nextcloud.com/?ref=docupoint.eu">Nextcloud</a> (European, self-hostable)</li><li>Messaging: <a href="https://signal.org/?ref=docupoint.eu">Signal</a> (while it lasts in Europe) or <a href="https://element.io/?ref=docupoint.eu">Element/Matrix</a></li><li>Search: <a href="https://www.ecosia.org/?ref=docupoint.eu">Ecosia</a> or <a href="https://www.qwant.com/?ref=docupoint.eu">Qwant</a> (European alternatives)</li><li>Browser: <a href="https://www.mozilla.org/firefox/?ref=docupoint.eu">Firefox</a> (nonprofit, privacy-focused)</li></ul><h3 id="demand-action">Demand action:</h3><ul><li>Contact your MEP about Chat Control: <a href="https://www.europarl.europa.eu/meps/en/home?ref=docupoint.eu">europarl.europa.eu/meps</a></li><li>Support digital rights organizations: <a href="https://edri.org/?ref=docupoint.eu">EDRi</a>, <a href="https://noyb.eu/?ref=docupoint.eu">noyb</a>, <a href="https://www.laquadraturedunet.org/en/?ref=docupoint.eu">La Quadrature du Net</a></li><li>Ask your employer: Where is our company data stored? Who can access it? What's our plan for digital sovereignty?</li></ul><h3 id="stay-informed">Stay informed:</h3><ul><li>Follow the Chat Control negotiations at <a href="https://chatcontrol.eu/?ref=docupoint.eu">chatcontrol.eu</a></li><li>Read the <a href="https://www.eff.org/issues/surveillance?ref=docupoint.eu">EFF's surveillance coverage</a></li><li>Support independent European tech journalism</li></ul><p>The superstates are forming. The perpetual war is already underway, fought not with bombs but with algorithms, not for territory but for attention, not for bodies but for minds.</p><p>The question is whether Europe will be a player or a province. A civilization or a colony. A fourth way or a footnote.</p><p>In Orwell's world, the clock struck thirteen and nobody noticed.</p><p>In our world, we can still hear the chimes, if we can tear ourselves away from our screens long enough to listen.</p><p><strong>The clock is striking. Will you keep scrolling?</strong></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222124.png" class="kg-image" alt="The Choice" loading="lazy" width="1208" height="702" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106222124.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106222124.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106222124.png 1208w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Choice: Two paths diverge from the clock striking thirteen</span></figcaption></figure><hr><h2 id="series-context">Series context</h2><p><strong>Position:</strong> Part 3 of 3 in "1984 → 2048: Europe's Choice" trilogy<br><strong>Previous:</strong> <a href="https://www.docupoint.eu/1984-2048-europe-under-siege/">1984 → 2048: Europe Under Siege (Part 2)</a><br><strong>Next:</strong> —</p><p>This concludes the "1984 → 2048: Europe's Choice" trilogy.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[SharePoint Storage Display: New &quot;Used&quot; View Reveals minor change]]></title>
                    <description><![CDATA[Microsoft has updated the SharePoint Admin Center storage display, flipping from &quot;X TB available of Y TB&quot; to &quot;X TB used of Y TB.&quot;

More notable: the breakdown now separately shows Microsoft SharePoint Embedded applications. First-party apps—Loop, Designer, Copilot Agents, Outlook Newsletters—consume tenant]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/sharepoint-storage-display-new-used-view-reveals-minor-change/</link>
                    <guid isPermaLink="false">6970d08d92d3660001ba4dc8</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[Microsoft 365]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 21 Jan 2026 14:22:40 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft has updated the SharePoint Admin Center storage display, flipping from "X TB available of Y TB" to "X TB used of Y TB."</p><p>More notable: the breakdown now separately shows <strong>Microsoft SharePoint Embedded applications</strong>. First-party apps—Loop, Designer, Copilot Agents, Outlook Newsletters—consume tenant quota through these containers. Many admins don't realize these tools draw from the same pool as SharePoint sites.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>What changed:</strong> Storage display now shows "Used" instead of "Available"<br><strong>New visibility:</strong> SharePoint Embedded app storage (Loop, Designer, Copilot Agents, Outlook Newsletters) shown separately<br><strong>Impact:</strong> Admins can see how first-party apps consume tenant SharePoint quota<br><strong>Action required:</strong> None. Display-only change</div></div><hr><h3 id="sources">Sources</h3><ul><li><a href="https://learn.microsoft.com/en-us/microsoft-365/admin/activity-reports/sharepoint-storage-reports?ref=docupoint.eu">SharePoint Storage Reports</a> – Microsoft Learn</li><li><a href="https://learn.microsoft.com/en-us/sharepoint/dev/embedded/administration/billing/meters?ref=docupoint.eu">SharePoint Embedded Billing</a> – Microsoft Learn</li><li>MC1072408 – Storage Insights in M365 Admin Center</li></ul>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Purview DLP Gets Adaptive Scopes for SharePoint Sites]]></title>
                    <description><![CDATA[Microsoft Purview DLP now supports adaptive scopes for SharePoint sites, enabling dynamic policy targeting based on site URL, name, or custom properties. Removes the 100-site static policy limit.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/purview-dlp-gets-adaptive-scopes-for-sharepoint-sites/</link>
                    <guid isPermaLink="false">6990f9d949431d0001e74210</guid>

                        <category><![CDATA[Radar]]></category>
                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[SharePoint Online]]></category>
                        <category><![CDATA[Microsoft Purview]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Wed, 21 Jan 2026 13:00:00 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft Purview DLP now supports adaptive scopes for SharePoint Online sites, allowing administrators to dynamically target DLP policies based on site attributes instead of manually selecting individual sites. Rolling out from late January through late February 2026.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Rollout:</strong> Late January to late February 2026<br><strong>What it does:</strong> Automatically includes/excludes SharePoint sites in DLP policies based on rules<br><strong>Targeting criteria:</strong> Site URL, site name, or custom SharePoint managed properties (RefinableString00-99)<br><strong>Key benefit:</strong> Removes the 100-site static policy limit<br><strong>Query language:</strong> Keyword Query Language (KQL)<br><strong>Limitation:</strong> Administrative units do not yet support SharePoint site scopes</div></div><hr><p>Previously, DLP policies for SharePoint sites required manually adding each site, with a hard cap of 100 sites per policy. Adaptive scopes evaluate site properties continuously and auto-include or exclude sites as they change. This is especially useful for large tenants where sites are created frequently and manual policy maintenance is impractical. The feature uses the same KQL syntax familiar from SharePoint search, configured through custom managed properties.</p><p><strong>Sources:</strong> <a href="https://learn.microsoft.com/en-us/purview/purview-adaptive-scopes?ref=docupoint.eu">Microsoft Learn</a> · <a href="https://office365itpros.com/2026/02/09/adaptive-scope-membership/?ref=docupoint.eu">Office 365 IT Pros</a> · <a href="https://sharepoint.handsontek.net/2026/02/01/whats-new-sharepoint-january-2026/?ref=docupoint.eu">HandsOnTek</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[1984 → 2048: Europe Under Siege]]></title>
                    <description><![CDATA[From Brexit to the AfD&#x27;s rise, this article traces how Russia has systematically cultivated European far-right movements while exploiting Europe&#x27;s digital dependency—a siege that aims to absorb the continent without firing a shot.]]></description>
                    <link>https://www.docupoint.eu/blog/1984-2048-europe-under-siege/</link>
                    <guid isPermaLink="false">695d814f05158200010a5081</guid>

                        <category><![CDATA[Digital Trust Wars]]></category>
                        <category><![CDATA[digital-sovereignty]]></category>
                        <category><![CDATA[surveillance]]></category>
                        <category><![CDATA[privacy]]></category>
                        <category><![CDATA[Security]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Mon, 19 Jan 2026 08:00:13 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" alt="1984 → 2048: Europe Under Siege"/> <p><em>Part 2 of 3 in the "1984 → 2048: Europe's Choice" trilogy</em></p><blockquote>"We are not interested in the good of others; we are interested solely in power."<br>— O'Brien to Winston Smith, <em>1984</em></blockquote><p>Brexit and Trump weren't the attack. They were the rehearsal.</p><p>In 2016, Russian intelligence tested its weapons on the Anglosphere, and both targets fell. The troll farms worked. The funding pipelines worked. The division algorithms worked. Now the arsenal is aimed at the continent those operations were designed to isolate.</p><p>Europe is the real target. The siege has already begun.</p><p>In <a href="https://www.docupoint.eu/1984-2048-three-digital-superstates/">Part 1</a>, we mapped the three digital superstates and their perpetual war. Now we turn to their primary battlefield: Europe.</p><p>The siege of Europe doesn't use tanks and missiles. It uses troll farms and bank transfers, compromised politicians and captured platforms. Russia has spent a decade cultivating far-right movements across the continent. America has built a surveillance infrastructure that treats European data as a resource to be extracted. China manufactures the hardware that enables both.</p><p>But Europe's greatest vulnerability isn't the superstates' aggression, it's Europe's own digital naivety. The continent that invented privacy as a human right has made itself utterly dependent on foreign platforms, foreign hardware, and foreign clouds.</p><p>In Orwell's <em>1984</em>, Europe doesn't exist. It has been absorbed: the west into Oceania, the east into Eurasia. That absorption is happening now, in real time, through mechanisms Orwell never imagined.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png" class="kg-image" alt="The Siege Begins" loading="lazy" width="1239" height="738" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220457.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220457.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220457.png 1239w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Siege Begins: Europe surrounded by digital forces</span></figcaption></figure><h2 id="the-long-game-from-crimea-to-cambridge-to-kyiv">The long game: from Crimea to Cambridge to Kyiv</h2><h3 id="the-documented-strategy-divide-and-conquer">The documented strategy: divide and conquer</h3><p>Russia's strategy to weaken Western unity is not speculation. It is doctrine. The "<a href="https://www.lawfaremedia.org/article/russias-far-right-campaign-europe?ref=docupoint.eu">Gerasimov Doctrine</a>" (named after Russian Chief of General Staff Valery Gerasimov) explicitly describes how information warfare, political subversion, and strategic ambiguity can achieve objectives that conventional military force cannot. The goal: <strong>fracture NATO and the EU before any shot is fired.</strong></p><p>The timeline tells the story:</p><ul><li><strong>2014: Crimea</strong> - Russia annexes Crimea while the West responds with sanctions but no military intervention. The message: the West is divided and will not fight.</li><li><strong>2016: Brexit &amp; Trump</strong> - Both campaigns saw documented Russian interference. The U.S. <a href="https://www.justice.gov/archives/sco/file/1373816/download?ref=docupoint.eu">Mueller Report</a> confirmed the Internet Research Agency (IRA) operated "troll farms" targeting American voters. UK intelligence identified the same Russian actors attempting to influence the Brexit referendum.</li><li><strong>2022: Ukraine</strong> - Full-scale invasion, betting that a divided West would fragment under economic pressure. The bet nearly worked.</li></ul><p>This is not a conspiracy theory. The <a href="https://www.dni.gov/files/documents/ICA_2017_01.pdf?ref=docupoint.eu">U.S. Intelligence Community's January 2017 assessment</a> concluded with "high confidence" that Russian President Vladimir Putin "ordered an influence campaign" targeting the 2016 U.S. election. The <a href="https://www.justice.gov/archives/sco/file/1373816/download?ref=docupoint.eu">Mueller Report</a> documented "sweeping and systematic" interference by the IRA, which created fake American personas on social media and organized real-world rallies on both sides of divisive issues.</p><h3 id="the-european-front-what-we-know">The European front: what we know</h3><h4 id="the-troll-farms-go-continental">The troll farms go continental</h4><p>The Internet Research Agency's operations targeted both the U.S. 2016 election and UK Brexit referendum simultaneously. The same St. Petersburg-based troll farm ran <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">concurrent influence campaigns across Western democracies</a>, creating fake personas, amplifying divisive content, and organizing real-world events on both sides of the Atlantic.</p><h4 id="following-the-money">Following the money</h4><p>Russian funding to European parties has been documented by the <a href="https://www.lawfaremedia.org/article/russias-far-right-campaign-europe?ref=docupoint.eu">European Parliament's "Tip of the Iceberg" report</a>. The French National Front (now RN) received <a href="https://www.opendemocracy.net/en/5050/russia-ukraine-war-putin-europe-far-right-funding-conservatives/?ref=docupoint.eu">€11 million in loans from Russian banks in 2014</a>. Austria's FPÖ signed a <a href="https://theconversation.com/unmarred-by-russian-spying-scandal-austrias-far-right-expected-to-cruise-to-victory-in-european-elections-231464?ref=docupoint.eu">formal "friendship agreement" with Putin's United Russia party in 2016</a>. The money trail is not speculation; it is documented.</p><h4 id="the-german-connection">The German connection</h4><p>AfD-Kremlin connections include documented meetings between party officials and Russian actors. In 2024, MEP Maximilian Krah was <a href="https://www.washingtonpost.com/world/2024/06/03/russia-europe-far-right-espionage/?ref=docupoint.eu">detained and questioned by the FBI</a> over suspicions of receiving Kremlin funds through the Voice of Europe operation. German intelligence continues to monitor these contacts.</p><h4 id="caught-on-camera">Caught on camera</h4><p>The Ibiza Scandal of 2019 captured Austria's FPÖ vice-chancellor on video discussing political donations from someone claiming to be a Russian oligarch's niece. The footage <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">exposed the eagerness for Kremlin money at the highest levels</a> of European politics. The vice-chancellor resigned within days.</p><h4 id="what-remains-unproven">What remains unproven</h4><p>Cambridge Analytica's role in Brexit remains contested. While documentaries have presented compelling narratives linking the data firm's Brexit work to its later Trump campaign involvement, the UK Information Commissioner's investigation found "no significant breaches" by the firm in the Brexit referendum context. The connection is plausible but not proven to the same standard as Internet Research Agency operations.</p><p>Direct coordination between Brexit, Trump campaigns, and the Kremlin has not been established with the same evidentiary standard as Russian interference itself. The operations may have been parallel rather than coordinated. We should be careful not to see conspiracy where opportunism may suffice as explanation.</p><h3 id="the-rightward-shift-coincidence-or-consequence">The rightward shift: coincidence or consequence?</h3><p>Since 2020, the same pattern has played out across Europe's largest democracies.</p><h4 id="germany-the-unthinkable-returns">Germany: the unthinkable returns</h4><p>The AfD won <a href="https://moderndiplomacy.eu/2025/03/07/shifting-tides-the-far-rights-rise-and-germanys-electoral-dilemma/?ref=docupoint.eu">20.8% in the 2025 federal election</a>, their best result ever. In September 2024, Thuringia became the site of the <a href="https://moderndiplomacy.eu/2025/03/07/shifting-tides-the-far-rights-rise-and-germanys-electoral-dilemma/?ref=docupoint.eu">first far-right state election victory in Germany since World War II</a>. Party leader Alice Weidel has <a href="https://www.dailysabah.com/world/europe/germanys-far-right-afd-vows-to-part-ways-with-eu-paris-deal-euro?ref=docupoint.eu">explicitly cited Brexit as a model for "Dexit"</a>, Germany's exit from the European Union. Meanwhile, German intelligence warns of <a href="https://www.washingtonpost.com/world/2024/06/03/russia-europe-far-right-espionage/?ref=docupoint.eu">ongoing Russian cultivation of AfD contacts</a>. The party that once seemed a fringe protest movement now shapes the national conversation.</p><h4 id="france-le-pens-long-march">France: Le Pen's long march</h4><p>Marine Le Pen's Rassemblement National won <a href="https://www.euronews.com/my-europe/2024/06/09/france-marine-le-pens-far-right-party-makes-historic-gains-in-eu-elections?ref=docupoint.eu">31.4% in the 2024 European Parliament elections</a>, their highest share since 1984. The party now holds <a href="https://en.wikipedia.org/wiki/National_Rally?ref=docupoint.eu">125 seats in the National Assembly</a> after the July 2024 snap elections—a historic breakthrough that would have been unimaginable a decade ago. Le Pen herself is currently <a href="https://www.britannica.com/biography/Marine-Le-Pen?ref=docupoint.eu">barred from the 2027 presidential run</a> due to an EU fund embezzlement conviction, but the movement she built has joined the <a href="https://europrospects.eu/patriots-for-europe-a-radical-right-shift-in-the-eus-political-landscape/?ref=docupoint.eu">Patriots for Europe group</a> alongside Hungarian Fidesz and Austrian FPÖ, forming a continental bloc.</p><h4 id="austria-through-the-looking-glass">Austria: through the looking glass</h4><p>The FPÖ won <a href="https://www.euronews.com/2025/01/06/austrias-president-tasks-far-right-fpo-leader-herbert-kickl-with-forming-new-government?ref=docupoint.eu">28.8% in the 2024 parliamentary elections</a>, their best result in history. <a href="https://www.euronews.com/2025/01/06/austrias-president-tasks-far-right-fpo-leader-herbert-kickl-with-forming-new-government?ref=docupoint.eu">Herbert Kickl has been tasked with forming Austria's first far-right-led government since World War II</a>. A former intelligence chief warned that FPÖ in government would be <a href="https://neweasterneurope.eu/2025/02/06/austrias-drift-toward-isolation-kickls-russia-ties-and-the-risk-of-following-hungarys-lead-in-the-war/?ref=docupoint.eu">"a considerable security problem" for international partners</a>. The party maintains <a href="https://theconversation.com/unmarred-by-russian-spying-scandal-austrias-far-right-expected-to-cruise-to-victory-in-european-elections-231464?ref=docupoint.eu">documented ties to Russia</a> despite claiming its "friendship treaty" with Putin's United Russia has expired.</p><h3 id="the-pattern-eu-critical-but-not-eu-exit">The pattern: EU-critical but not EU-exit</h3><p>What makes the current shift strategically sophisticated is that these parties <a href="https://carnegieendowment.org/research/2024/04/charting-the-radical-rights-influence-on-eu-foreign-policy?ref=docupoint.eu">no longer explicitly call for EU exit</a>. They learned from Brexit's chaos. Instead, they advocate for a "Europe of sovereign nations" rather than federalism, demanding "national priority" for citizens over EU residents. They push for opt-outs from common policies on asylum, climate, and defense. They assert the primacy of national law over EU law, despite treaty violations. And they work to block further EU integration and enlargement at every turn.</p><p>This is the 1984 strategy adapted for 2026: <strong>You don't need to physically conquer territory if you can hollow out the institutions from within.</strong></p><h3 id="critical-assessment-causation-vs-correlation">Critical assessment: causation vs. correlation</h3><p>Is the European rightward shift caused by Russian interference, or is Russia simply exploiting existing discontent? The honest answer: <strong>both, and the distinction matters less than we'd like.</strong></p><h4 id="what-we-know">What we know</h4><p>Russian state actors have <a href="https://icct.nl/project/russias-influence-europes-far-right-violent-extremism?ref=docupoint.eu">systematically funded, promoted, and coordinated</a> with European far-right parties. These parties promote <a href="https://carnegieendowment.org/research/2024/04/charting-the-radical-rights-influence-on-eu-foreign-policy?ref=docupoint.eu">policies aligned with Russian strategic interests</a>: weaken NATO, fragment the EU, end Ukraine support. The timing of Russian interference correlates with major electoral disruptions, from <a href="https://securingdemocracy.gmfus.org/russia-is-still-finding-willing-partners-throughout-europe/?ref=docupoint.eu">Brexit to Trump in 2016</a>. Security services across Europe have issued <a href="https://neweasterneurope.eu/2025/02/06/austrias-drift-toward-isolation-kickls-russia-ties-and-the-risk-of-following-hungarys-lead-in-the-war/?ref=docupoint.eu">warnings about far-right parties' Russian connections</a>.</p><h4 id="what-we-cannot-prove">What we cannot prove</h4><p>We cannot definitively prove that Brexit or Trump would not have happened without Russian interference. We cannot prove that Cambridge Analytica's techniques were developed on Brexit and then deployed for Trump. We cannot prove that there is a single coordinated "master plan" rather than opportunistic exploitation. Correlation is not causation, and intellectual honesty requires acknowledging the limits of our evidence.</p><h4 id="the-conclusion-that-matters">The conclusion that matters</h4><p>Whether or not Russia "caused" Europe's rightward shift, it has <a href="https://icct.nl/publication/russia-and-far-right-insights-ten-european-countries?ref=docupoint.eu">demonstrably amplified and exploited it</a>. The parties most aligned with Russian interests are <a href="https://time.com/7301526/europe-far-right-momentum/?ref=docupoint.eu">gaining power across the continent</a>. The policies they promote would achieve Orwell's Eurasia outcome, European absorption into the Russian sphere, through democratic means rather than military conquest.</p><p><em>In 1984, Big Brother conquered through force. In 2026, the conquest can come through the ballot box.</em></p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220637.png" class="kg-image" alt="The Rightward March" loading="lazy" width="1200" height="738" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220637.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220637.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220637.png 1200w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Rightward March: Democracy's mechanisms turned against itself</span></figcaption></figure><hr><h2 id="the-real-vulnerability-european-digital-naivety">The real vulnerability: European digital naivety</h2><p>Here's what Europeans must confront: <strong>Russia didn't build the weapons it uses against us. We handed them over.</strong></p><p>Russia's <a href="https://en.wikipedia.org/wiki/Internet_Research_Agency?ref=docupoint.eu">Internet Research Agency</a> troll farms operated on American platforms (Facebook, Twitter, YouTube) that Europe adopted wholesale without building alternatives. The disinformation that fractures European unity flows through infrastructure we don't control, governed by algorithms we can't audit, owned by companies that answer to foreign courts.</p><p><strong>This wasn't inevitable. Other regions made different choices.</strong></p><p><a href="https://www.theegg.com/seo/korea/search-engine-market-share-in-korea?ref=docupoint.eu">South Korea</a>, a country of 51 million people, built and maintained its own digital ecosystem. <a href="https://www.interad.com/en/insights/korean-search-engine-market-share?ref=docupoint.eu">Naver dominates search with 63% market share</a> (Google has just 31%). <a href="https://www.meltwater.com/en/blog/korean-social-media?ref=docupoint.eu">KakaoTalk is the universal messaging app</a>: virtually every Korean uses it. Naver and Kakao together control <a href="https://admaru.com/2024/02/12/uniqueness-of-the-korean-programmatic-market/?ref=docupoint.eu">over 70% of Korea's digital advertising market</a>, forming what analysts call a "walled garden" that limits American platform dominance.</p><p><a href="https://blog.hubspot.com/marketing/social-media-platforms-that-werent-founded-in-the-us?ref=docupoint.eu">Japan built LINE</a> with 186 million users across Asia, dominating messaging in Japan, Taiwan, and Thailand. <a href="https://globibo.com/et/country-specific-social-media/?ref=docupoint.eu">Russia has VK</a> (72 million users) and Telegram. <a href="https://www.ecinnovations.com/blog/social-media-around-the-world-20-country-specific-platforms-you-need-to-know-in-2025/?ref=docupoint.eu">China's ecosystem</a> (WeChat with 1.28 billion users, Weibo, Douyin) is entirely domestic.</p><p>Europe could resist. With 450 million people and a €17 trillion economy, it had the market power to demand alternatives or build its own. It chose dependency.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220830.png" class="kg-image" alt="The Dependency Trap" loading="lazy" width="1248" height="678" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/Pasted-image-20260106220830.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/Pasted-image-20260106220830.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260106220830.png 1248w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">The Dependency Trap: 450 million people. Zero major platforms.</span></figcaption></figure><p>Russia is merely the most aggressive exploiter of a vulnerability that <em>all three superstates</em> recognize:</p><h3 id="the-three-enablers-of-european-weakness">The three enablers of European weakness</h3><p><strong>1. Social Media Colonization</strong> - Europe has no major social platforms. <a href="https://www.statista.com/statistics/745400/facebook-europe-mau-by-quarter/?ref=docupoint.eu">Facebook has 308 million European users</a>, <a href="https://newsroom.tiktok.com/en-eu/150-m-people-across-europe-come-to-tiktok-every-month?ref=docupoint.eu">TikTok 150 million</a>. When Russian trolls, Chinese influence operations, or American political campaigns want to reach European citizens, they use American platforms that European regulators can fine but not fundamentally control. The DSA is a bandage on a severed limb.</p><p><strong>2. Hardware Dependency</strong> - Europe designs chips (ASML's lithography machines are essential to every advanced processor), but <a href="https://digital-strategy.ec.europa.eu/en/policies/european-chips-act?ref=docupoint.eu">manufactures almost none</a>. Chinese factories build the phones in European pockets. The surveillance capabilities baked into hardware, whether <a href="https://www.cfr.org/backgrounder/huawei-chinas-controversial-tech-giant?ref=docupoint.eu">Chinese backdoors feared by Western intelligence</a> or <a href="https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order?ref=docupoint.eu">American ones revealed by Snowden</a>, exist in devices Europe cannot inspect at scale.</p><p><strong>3. Cloud Subjugation</strong> - <a href="https://www.srgresearch.com/articles/european-cloud-providers-continue-to-grow-but-still-lose-market-share?ref=docupoint.eu">Seven out of every ten bytes</a> of European data live on American servers. When Washington sneezes, Berlin's email goes down. When Amazon has a bad quarter, European startups lose their infrastructure. European data is subject to the <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">CLOUD Act</a>, accessible to American intelligence, governed by American law. When Microsoft can <a href="https://www.politico.eu/article/microsoft-suspends-international-criminal-court-icc-email-services/?ref=docupoint.eu">suspend the International Criminal Court's email</a>, and AWS can <a href="https://www.cnbc.com/2021/01/16/how-parler-deplatforming-shows-power-of-cloud-providers.html?ref=docupoint.eu">deplatform any customer within 24 hours</a> as it did with Parler, European sovereignty is revealed as a polite fiction.</p><h3 id="the-superstates-dont-compete-for-europe-they-share-it">The Superstates Don't Compete for Europe, they share it</h3>
<!--kg-card-begin: html-->
<table>
<thead>
<tr><th>Vulnerability</th><th>American Exploitation</th><th>Russian Exploitation</th><th>Chinese Exploitation</th></tr>
</thead>
<tbody>
<tr><td>Social media</td><td>Platform monopoly, data harvesting, algorithmic control</td><td>Disinformation campaigns, political manipulation</td><td>TikTok influence, propaganda amplification</td></tr>
<tr><td>Hardware</td><td>NSA-accessible devices, supply chain leverage</td><td>Limited (depends on Western tech)</td><td>Manufacturing dominance, potential backdoors</td></tr>
<tr><td>Cloud/Data</td><td>CLOUD Act access, surveillance infrastructure</td><td>Cyberattacks on European systems</td><td>Data requirements for market access</td></tr>
<tr><td>Surveillance model</td><td>Corporate extraction ("surveillance capitalism")</td><td>State-directed information warfare</td><td>State-corporate fusion, exported globally</td></tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>The question isn't whether Russia, America, or China poses the greater threat. <strong>The question is why Europe built a digital civilization on foundations it doesn't control.</strong></p><p>Russia weaponizes European vulnerabilities. America monetizes them. China manufactures the hardware that enables both.</p><p><strong>Europe's 1984 nightmare isn't being conquered by one superstate. It's being colonized by all three simultaneously, each taking the piece that serves its interests.</strong></p><hr><h2 id="europes-1984-nightmare">Europe's 1984 nightmare</h2><h3 id="in-orwells-world-europe-doesnt-exist">In Orwell's world, Europe doesn't exist</h3><p>This is not metaphor. Open <em>1984</em> and look at the map Orwell drew.</p><p>Oceania comprises the Americas, the British Isles, Australasia, and southern Africa. Eurasia spans the entire Eurasian landmass from Portugal to the Bering Strait. Eastasia covers China, Japan, and Southeast Asia.</p><p><strong>Where is Europe?</strong></p><p>Western Europe—France, Germany, the Low Countries, Scandinavia—is a perpetual warzone, fought over but never truly held. In the novel's backstory, Britain was absorbed into Oceania (the American sphere) in the 1950s. Continental Europe fell to Eurasia (the Russian sphere). The European civilization that gave the world the Enlightenment, human rights, and democratic governance simply... ceased to exist as an independent entity.</p><p>Orwell wrote this in 1948, projecting forward to 1984. He was describing the logic of superpower competition: <strong>small and medium powers get absorbed or destroyed.</strong> There is no room for a third way.</p><p>We are now living the test of whether Orwell was wrong.</p><h3 id="the-current-trajectory-digital-absorption-in-progress">The current trajectory: digital absorption in progress</h3><p>The absorption Orwell imagined through military conquest is happening through digital dependency:</p><ul><li>Seven of every ten bytes of EU data live on American servers</li><li>Energy dependence was Russian until 2022, and the pipelines can't be unbuilt overnight</li><li>The phone in your pocket was assembled in China, from chips designed in America, running software that reports to both</li><li>Your political opinions are shaped by American algorithms and disrupted by Russian operations</li></ul><p>Europe in 2026: a digital colony caught between empires, each taking what it needs.</p><h3 id="the-pretty-version-of-1984">The "Pretty Version" of 1984</h3><p>Orwell got one thing wrong: he assumed totalitarianism would be ugly.</p><p>In 1984, the Party rules through deprivation, fear, and violence. The telescreens are mandatory. The Two Minutes Hate is compulsory. Room 101 breaks the body to conquer the mind. The boot stamps on a human face, forever.</p><p><strong>But history teaches a different lesson: empires built on violence eventually fall. Empires built on desire endure.</strong></p><p>The Soviet Union fell because it could not provide what people wanted—consumer goods, freedom, opportunity. The American cultural empire spread through <a href="https://www.foreignaffairs.com/articles/united-states/1998-05-01/soft-power?ref=docupoint.eu">blue jeans, Coca-Cola, and Hollywood</a>, things people chose to embrace. You cannot sustain an empire that only takes. The empires that last are the ones that give people what they desire, then extract value from the dependency they create.</p><p>In 2026, control wears a friendlier face:</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr><th>1984</th><th>2026</th></tr>
</thead>
<tbody>
<tr><td><strong>Telescreen</strong> (mandatory, watched you)</td><td><strong>Smartphone</strong> (voluntary, you bought it, you carry it everywhere)</td></tr>
<tr><td><strong>Two Minutes Hate</strong> (compulsory outrage)</td><td><strong>Algorithmic feed</strong> (voluntary outrage, optimized for engagement)</td></tr>
<tr><td><strong>Room 101</strong> (torture with your deepest fear)</td><td><strong>Dopamine loops</strong> (reward with your deepest desires)</td></tr>
<tr><td><strong>Newspeak</strong> (vocabulary reduction)</td><td><strong>Content curation</strong> (information bubbles, reality fragmentation)</td></tr>
<tr><td><strong>Ministry of Truth</strong> (central propaganda)</td><td><strong>Personalized reality</strong> (each user sees different "truth")</td></tr>
<tr><td><strong>Thought Police</strong> (surveillance for dissent)</td><td><strong>Predictive analytics</strong> (surveillance for profit and influence)</td></tr>
<tr><td><strong>Boot on face</strong> (painful control)</td><td><strong>Comfortable sneaker</strong> (frictionless submission)</td></tr>
</tbody>
</table>
<!--kg-card-end: html-->
<figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-4.png" class="kg-image" alt="" loading="lazy" width="1215" height="745" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/image-4.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/image-4.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-4.png 1215w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Both images show control. Only one face knows it.</span></figcaption></figure><p>The Party understood that humans can be broken by pain. Silicon Valley discovered they can be captured by pleasure. The result is the same: a population that cannot think clearly, cannot act collectively, cannot resist effectively.</p><p><strong>We are not tortured into compliance. We are entertained into it.</strong></p><hr><h2 id="doublethink-in-the-digital-age">Doublethink in the digital age</h2><p>In 1984, "doublethink" means holding two contradictory beliefs simultaneously and accepting both as true. <em>War is Peace. Freedom is Slavery. Ignorance is Strength.</em></p><p>Each superstate practices its own version:</p><p><strong>America</strong> declares privacy a fundamental right while operating PRISM, <a href="https://www.theguardian.com/world/2013/oct/23/us-monitored-angela-merkel-german?ref=docupoint.eu">tapping Angela Merkel's phone</a>, and passing the <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943?ref=docupoint.eu">CLOUD Act</a> to reach any data stored by American companies, anywhere in the world. Rules-based international order, except when American interests say otherwise.</p><p><strong>China</strong> demands non-interference in its internal affairs while exporting surveillance systems to <a href="https://freedomhouse.org/report/freedom-net/2023/repressive-power-artificial-intelligence?ref=docupoint.eu">80+ countries</a>. The cameras that watch Uyghurs in Xinjiang now watch dissidents in Zimbabwe. Belt and Road promises "win-win cooperation", until <a href="https://www.nytimes.com/2018/06/25/world/asia/china-sri-lanka-port.html?ref=docupoint.eu">Sri Lanka loses a port</a> and Zambia offers its electrical grid as collateral.</p><p><strong>Russia</strong> claims NATO expansion threatens its security while invading Georgia, annexing Crimea, and launching full-scale war against Ukraine. It justifies the invasion as "denazification" while <a href="https://www.bbc.com/news/world-europe-65851734?ref=docupoint.eu">employing the Wagner Group</a>, whose founder displayed Nazi insignia. It demands information sovereignty while <a href="https://www.justice.gov/archives/sco/file/1373816/download?ref=docupoint.eu">operating troll farms</a> that flood Western social media with disinformation.</p><p>For Europeans, the challenge is not choosing the "good" side. There is no good side. Each superstate speaks of values while practicing power. Both surveil. Both extract. Both subordinate European interests to their own.</p><p>Winston Smith was taught to accept that 2 + 2 = 5 if the Party said so. Europeans are being asked to accept that surveillance is privacy, that dependency is partnership, that absorption is alliance.</p><p>The answer must be: <strong>No. We can count.</strong></p><hr><p>The siege is real. The walls are breached.</p><p>Russia cultivates politicians who would dismantle the EU from within. America extracts data through platforms we cannot control. China manufactures the devices we cannot inspect. And Europe—450 million people, €17 trillion in GDP—has made itself dependent on all three.</p><p>In Orwell's <em>1984</em>, Winston Smith asks O'Brien what the future looks like. The answer: "A boot stamping on a human face, forever."</p><p>But that was the ugly version. The version that breeds resistance.</p><p>The 2026 version is different. The boot is a comfortable sneaker. The stamping is a gentle massage. The human face is scrolling, always scrolling, too entertained to notice what it has surrendered.</p><p><strong>But Europe is not Oceania. Not yet.</strong></p><p>In <a href="https://www.docupoint.eu/1984-2048-the-fourth-way/">Part 3: The Fourth Way</a>, we examine what Europe still possesses that Winston Smith never had: democratic institutions, regulatory power, 450 million citizens who can still choose.</p><hr><h2 id="series-context">Series context</h2><p><strong>Position:</strong> Part 2 of 3 in "1984 → 2048: Europe's Choice" trilogy<br><strong>Previous:</strong> <a href="https://www.docupoint.eu/1984-2048-three-digital-superstates/">1984 → 2048: The Three Digital Superstates (Part 1)</a><br><strong>Next:</strong> <a href="https://www.docupoint.eu/1984-2048-the-fourth-way/">1984 → 2048: The Fourth Way (Part 3)</a></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[SharePoint User Permission Reports are finally here]]></title>
                    <description><![CDATA[After 25 years, SharePoint finally offers native user-centric permission reports. Here&#x27;s what they can do, what they can&#x27;t, and when third-party tools remain the better choice.]]></description>
                    <link>https://www.docupoint.eu/blog/sharepoint-user-permission-reports-are-finally-here/</link>
                    <guid isPermaLink="false">696c13f7d0f84a0001ba0a64</guid>

                        <category><![CDATA[SharePoint Online]]></category>
                        <category><![CDATA[microsoft]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sun, 18 Jan 2026 16:00:30 +0100</pubDate>

                        <media:content url="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/SharePoint-User-Permission-Reports-are-finally-here.jpg" medium="image"/>

                    <content:encoded><![CDATA[<img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/SharePoint-User-Permission-Reports-are-finally-here.jpg" alt="SharePoint User Permission Reports are finally here"/> <p>For 25 years, answering "What can this user access?" in SharePoint required PowerShell scripts or third-party tools. That changed in late 2025 when Microsoft added user-centric permission snapshot reports to the SharePoint Admin Center.</p><p>The feature is genuinely useful, and has clear limitations. Here's what administrators need to know.</p><h2 id="what-microsoft-now-offers">What Microsoft now offers</h2><p>The Data Access Governance reports in SharePoint Admin Center include three snapshot report types:</p><p><strong>Site permissions for your organization</strong> provides a tenant-wide view of permission structures, total users per site, guest access, "Everyone except external users" exposure, and sharing link counts.</p><p><strong>Site permissions for users</strong> answers the user-centric question: given a specific person, which sites can they access? The report distinguishes between site-level and item-level access, showing whether permissions were granted directly or through groups.</p><p><strong>Sensitivity labels for files</strong> identifies sites containing files with specific sensitivity labels.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-5.png" class="kg-image" alt="" loading="lazy" width="2000" height="1125" srcset="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w600/2026/01/image-5.png 600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1000/2026/01/image-5.png 1000w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/size/w1600/2026/01/image-5.png 1600w, https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/image-5.png 2000w" sizes="(min-width: 720px) 720px"></figure><h2 id="licensing-requirements">Licensing requirements</h2><p>These reports require SharePoint Advanced Management (SAM) licensing at $3 per user per month, licensed for every user in the tenant. For a 150-person organization, that's $5,400/year.</p><p>Organizations with at least one Microsoft 365 Copilot license ($30/user/month) automatically receive SAM features for all administrators—Microsoft positioned these tools as Copilot readiness features for auditing permissions before AI can surface sensitive content.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/39/1a/391adeaa-2eb4-44f2-a44f-757bcbe900c6/content/images/2026/01/Pasted-image-20260117235106-2-1.png" class="kg-image" alt="" loading="lazy" width="503" height="237"></figure><h2 id="key-limitations">Key limitations</h2><p>Even with SAM licensed, these reports have constraints:</p><ul><li><strong>30-day refresh cycle</strong> — reports can only be regenerated monthly</li><li><strong>48-hour data latency</strong> — reports capture data from up to 48 hours before generation</li><li><strong>Maximum 5 concurrent reports</strong> — you cannot generate unlimited user reports</li><li><strong>No change tracking</strong> — snapshot reports show current state, not who changed permissions or when</li><li><strong>CSV export only</strong> — no native Power BI integration, alerting, or automated workflows</li></ul><h2 id="third-party-alternatives">Third-party alternatives</h2><p>For organizations needing more than monthly snapshots, several established tools fill the gaps:</p><ul><li><a href="https://www.syskit.com/products/point/?ref=docupoint.eu"><strong>Syskit Point</strong></a> offers comprehensive permission management with automated access reviews, lifecycle management, and detailed audit trails. Strong integration with Microsoft 365 governance workflows.</li><li><a href="https://lightningtools.com/products/sharepoint-online-permissions-management-tool/?ref=docupoint.eu"><strong>DeliverPoint</strong></a> runs as an SPFx solution entirely within your tenant, no data export required. Provides real-time reporting, permission snapshots with point-in-time recovery, and site owner self-service.</li><li><a href="https://sharegate.com/?ref=docupoint.eu"><strong>ShareGate</strong></a> combines migration capabilities with permission reporting. The Permissions Matrix Report provides cross-site visibility without PowerShell.</li><li><a href="https://www.cognillo.com/sharepoint-permissions-tool?ref=docupoint.eu"><strong>Cognillo SharePoint Essentials Toolkit</strong></a> offers a free community edition with permission reports at site, list, and item level—accessible for smaller organizations evaluating their needs.</li><li><a href="https://www.solarwinds.com/access-rights-manager?ref=docupoint.eu"><strong>SolarWinds Access Rights Manager</strong></a> provides enterprise-grade access governance across multiple platforms, with automated compliance reporting and scheduled audit delivery.</li><li><a href="https://www.manageengine.com/sharepoint-management-reporting/?ref=docupoint.eu"><strong>ManageEngine SharePoint Manager Plus</strong></a> supports hybrid environments (SharePoint Online plus on-premises 2013-SE), with scheduled reporting and secure delegation to technicians.</li></ul><h2 id="quick-comparison">Quick comparison</h2>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Capability</th>
<th>Microsoft Native</th>
<th>Third-Party Tools</th>
</tr>
</thead>
<tbody>
<tr>
<td>User-centric reports</td>
<td>✓</td>
<td>✓</td>
</tr>
<tr>
<td>Real-time reporting</td>
<td>✗ (48h delay)</td>
<td>✓</td>
</tr>
<tr>
<td>Daily snapshots</td>
<td>✗ (30-day minimum)</td>
<td>✓</td>
</tr>
<tr>
<td>Permission change tracking</td>
<td>Limited</td>
<td>✓</td>
</tr>
<tr>
<td>Automated alerts</td>
<td>✗</td>
<td>✓</td>
</tr>
<tr>
<td>Site owner self-service</td>
<td>✗</td>
<td>✓ (some tools)</td>
</tr>
<tr>
<td>Hybrid environment support</td>
<td>✗</td>
<td>✓ (some tools)</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<h2 id="when-to-use-what">When to use what</h2><p><strong>Microsoft's native reports are sufficient when you:</strong></p><ul><li>Already have Copilot licenses (SAM included)</li><li>Need quarterly or monthly permission audits</li><li>Focus primarily on Copilot readiness assessments</li><li>Have straightforward permission structures without frequent changes</li></ul><p><strong>Third-party tools are essential when you:</strong></p><ul><li>Require daily or real-time permission visibility</li><li>Need permission change auditing with historical tracking</li><li>Want site owners to self-manage permission hygiene</li><li>Operate hybrid SharePoint environments</li><li>Have compliance requirements demanding continuous monitoring</li><li>Need automated alerting on permission changes</li></ul><h2 id="practical-recommendation">Practical recommendation</h2><p>Microsoft's native reports fill a 25-year gap and provide genuine value for periodic organizational assessments and Copilot preparation. For basic quarterly audits, they're now sufficient.</p><p>Organizations with mature governance requirements, daily auditing, change tracking, automated compliance workflows, or hybrid environments—will find the native capabilities too constrained.</p><p>The most practical approach may be hybrid: use Microsoft's native reports for periodic tenant-wide assessments while deploying a specialized tool for continuous governance in high-sensitivity areas.</p><p>After 25 years, we finally have native user permission reports. They won't solve everything, but they're a solid foundation.</p><hr><p><strong>Sources:</strong></p><ul><li><a href="https://learn.microsoft.com/en-us/sharepoint/data-access-governance-site-permissions-users-report?ref=docupoint.eu">Microsoft Learn: Site permissions for users report</a></li><li><a href="https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports?ref=docupoint.eu">Microsoft Learn: Data access governance reports</a></li><li><a href="https://learn.microsoft.com/en-us/sharepoint/sharepoint-advanced-management-licensing?ref=docupoint.eu">Microsoft Learn: SAM Licensing</a></li></ul>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Native User Permission Reports Now Available in SharePoint Admin Center]]></title>
                    <description><![CDATA[Microsoft introduces native user-centric permission snapshot reports in SharePoint Admin Center. Shows all sites a specific user can access. Requires SharePoint Advanced Management or Copilot license.]]></description>
                    <link>https://www.docupoint.eu/microsoft365/sharepoint-online/native-user-permission-reports-now-available-in-sharepoint-admin-center/</link>
                    <guid isPermaLink="false">696c1079d0f84a0001ba0a5a</guid>

                        <category><![CDATA[SharePoint]]></category>
                        <category><![CDATA[Radar]]></category>

                        <dc:creator><![CDATA[Ulrich Bojko]]></dc:creator>

                    <pubDate>Sat, 17 Jan 2026 23:43:05 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Microsoft has introduced native user-centric permission reporting in the SharePoint Admin Center. For the first time in 25 years, administrators can generate reports showing all sites a specific user can access directly from the admin center.</p><hr><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">ℹ️</div><div class="kg-callout-text"><strong>Key Facts:</strong><br><strong>Feature:</strong> Site permissions for users report<br><strong>Scope:</strong> Lists all SharePoint and OneDrive sites accessible by specified users<br><strong>Granularity:</strong> Shows site-level vs. item-level access, direct vs. inherited permissions<br><strong>License required:</strong> SharePoint Advanced Management ($3/user/month) or Microsoft 365 Copilot license<br><strong>Limitations:</strong> Maximum 5 reports, 30-day refresh cycle, up to 48-hour data delay</div></div><hr><p>The report is part of Microsoft's Data Access Governance snapshot reports, designed to help organizations audit permissions before Copilot deployments or during employee departures. Administrators can specify up to several users per report and download results as CSV files containing detailed permission breakdowns including Microsoft Entra group memberships and sharing link counts.</p><p>While this marks significant progress for native tooling, the 30-day refresh limitation and SAM licensing requirement may keep third-party tools relevant for organizations needing daily permission auditing.</p><p><strong>Sources:</strong> <a href="https://learn.microsoft.com/en-us/sharepoint/data-access-governance-site-permissions-users-report?ref=docupoint.eu">Microsoft Learn - User Report</a> · <a href="https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports?ref=docupoint.eu">Data Access Governance Overview</a></p>]]></content:encoded>
                </item>
    </channel>
</rss>