"What is needed for the country to be truly digitally sovereign?
Artificial intelligence (AI) has become a key digital technology within just a few years. The impact of AI extends far beyond information technology – it is transforming the entire world of work, changing how and what we teach and learn, what we think we know about the world, how we research and create new things, and how and what we communicate with each other. This influence gives the nations, companies, and research institutions that are leaders in AI development an unprecedented position of power.
We experienced something similar about 70 years ago, when computers began to revolutionize our lives. Back then, we missed the opportunity to become a leading information technology nation and have been lamenting our lack of digital sovereignty ever since. AI now offers a second chance: It, too, is transforming the world, but is still so early in its development that there is (still) a very realistic chance of joining the leadership group.
To achieve this, it is necessary to embark on the further development of so-called foundational models. These contain the general language, knowledge, and problem-solving capabilities on which most modern AI applications are based. Foundational models are "pre-trained" by their providers, meaning they are fed with as much high-quality data as possible, such as articles, books, research databases, websites, and social media content. For specific applications, the foundational models must then be fine-tuned, for example, through continuous training with domain-specific data. They must be integrated into the customer's IT environment and constantly monitored there.
Whoever controls these foundational models and their training sets the rules of the digital world.
Current leaders are American companies such as OpenAI (GPT), Google (Gemini), Anthropic (Claude), and Meta (Llama). Leaders also are Chinese companies such as Baidu (ERNIE), Alibaba (Qwen), Huawei (Pangu), and DeepSeek.
Currently, the largest German foundational model is Luminous Supreme from Aleph Alpha, which, with 70 billion parameters is significantly smaller than the aforementioned baseline models from the United States. By comparison: Llama-3 has up to 405 billion parameters, while GPT-4 is sometimes estimated at 1.76 trillion, although it uses a special architecture. These size differences are significant. And this has consequences: Larger baseline models can generally capture more patterns from the training data, which can lead to better contextual understanding and fewer errors.
Germany must develop and operate a national AI infrastructure with its own, competitive baseline models to avoid remaining permanently dependent on American and Chinese providers. In addition to excellent research and development and sufficient skilled workers, this requires a network of AI data centers. These include several so-called AI gigafactories for training the baseline models and several regional, smaller AI data centers for adapting and operating the models (inference). The costs for this are enormous: Each AI gigafactory is expected to contain at least 100,000 specialized computing units, mostly so-called GPUs, and is expected to cost three to five billion euros.
The operating costs are dominated by the energy costs – not good news given the extremely high electricity costs in Germany after conflict with Russia.
According to estimates by the International Energy Agency, current AI data centers require approximately as much energy as 100,000 average households, and the trend is rising.
Training a large basic model currently costs between several tens and several hundred million euros. Adding everything together, the US is currently investing several hundred billion euros per year in research and development and infrastructure for AI, primarily from the private sector.
China lags somewhat behind, with other countries such as Japan, South Korea, Saudi Arabia, and the United Arab Emirates, as well as France, currently significantly increasing their investments. A lot of money is therefore needed, but with the right strategy, Germany can become one of the top AI nations by 2030.
As long as we do not develop our own top-class basic models, we will depend on what is available from America and China. The risks of such dependencies are concrete and diverse. A language model developed abroad can, consciously or unconsciously, introduce foreign values into German administrative processes, education systems, or the judiciary. Models based on a different legal culture could distort decisions in social administration. Medical systems trained on data from another population group could lead to misdiagnoses in German hospitals. Narrative distortions in training data can also influence the historical narrative in the media, schools, and universities.
Added to this is the risk of political influence: If search systems or language systems developed outside of Germany dominate in public administration or education, they can, in the long term, reinforce narratives that do not conform to our own democratic principles. This dependence is also economically dangerous: providers can dictate prices, restrict access, or change interfaces. Such mechanisms can be used deliberately as an instrument of hybrid warfare, for example, to deepen social divisions, undermine trust in institutions, or subtly steer public debates in a desired direction.
It could be argued that European regulations such as the General Data Protection Regulation and the AI Act define strong guardrails that provide safeguards and give European providers a market advantage. However, similar considerations in other IT areas have had little impact on the global market and the success of the European IT industry. The risks mentioned certainly cannot be addressed through legal means alone.
Germany therefore needs a comprehensive AI strategy. How can the country become one of the leading AI nations by 2030?
First, Germany—both the government and the private sector—must provide sufficient financial resources for the gradual development and operation of the national AI infrastructure outlined above, spread over five to seven years. To keep costs for the German government as low as possible, this infrastructure should be embedded in a larger European network and co-financed by the private sector—similar to what the EU requires for funding AI gigafactories. Nevertheless, a lot of money is required. But realistically, we would have to invest this money one way or another, if not in our own infrastructure, then in that of providers in the United States and China.
The technology for the data centers, especially GPUs, currently comes primarily from the United States, which means that in the long term, it would be desirable to achieve greater independence in the area of AI hardware as well.
Second, we must make the extensive data resources we have in Germany and Europe accessible for training general and specialized AI models. Ultimately, it is this data that determines the value of the models and gives us back control. This requires a pragmatic approach to data and copyright protection, which in turn requires appropriate curation mechanisms, cyber-secure and trustworthy data spaces, and fair business models for these data spaces.
Third: For such an infrastructure to be strategically effective, it must work closely with a strong, excellently networked research landscape. Significantly more AI specialists must be trained, and relevant AI aspects must be considered in all study and training subjects. Only in this way can computing power and data be transformed into truly powerful and trustworthy AI systems. Since generative AI is still in its infancy and its development depends on scientific progress, research excellence is particularly important for future competitiveness. Thanks to targeted public funding, Germany is doing quite well in AI research, with research institutions such as the German Research Center for Artificial Intelligence (DFKI) and various university centers funded by the federal and state governments, for example, hessian.ai in Hesse. The Innovation Park Artificial Intelligence (IPAI) is being built in Heilbronn with funding from the Dieter Schwarz Foundation. It will bring together leading AI players from business and science. Research is needed not only in machine learning, but also in the underlying computer science techniques and applications, high-performance computing, "green IT," quantum computing, and cybersecurity.
Fourth: Cybersecurity and resilience must be considered from the outset during the construction and operation of the AI infrastructure. The threat landscape for a national AI infrastructure is complex and ranges from state interference to criminal attacks. State actors could attempt to gain access to valuable models and training data through espionage, deliberately sabotage training processes, or insert hidden backdoors into models to create long-term access opportunities. So-called denial-of-service attacks on critical infrastructure can disrupt or completely paralyze operations. Criminal groups rely on ransomware to blackmail data centers, steal models for lucrative resale or use secured resources for cryptojacking. Added to this is industrial espionage: Foreign competitors could specifically target German innovations, supported by insiders in companies or research institutions, or through supply chain attacks via manipulated hardware components. An effective national AI strategy must address these threats from the outset and view cybersecurity not as an afterthought, but as an integral component of the overall architecture. A national AI infrastructure should therefore be designed to be secure from the outset.
So-called zero-trust architectures, centralized security operations, hardware security modules, continuous red teaming, and physical security and situational awareness are essential. Given their strategic importance, the systems must also be prepared against future threats such as quantum attacks. In the long term, certifications must be established that regularly test the security and trustworthiness of the infrastructure.
Fifth: Standardization within the national AI infrastructure is necessary as early as possible. Federal fragmentation risks duplicate procurement, incompatible systems, inefficient utilization, and security gaps. In Canada, the parallel development of federal and provincial AI platforms failed due to incompatibilities; only a national "Digital Research Alliance" provided a remedy. In Germany, the 16 different state school platforms demonstrate the costs and inefficiency of such fragmentation. For science and application, centralization means a uniform technical basis, fair resource allocation, high utilization, and uniform security standards. It makes the infrastructure a clear, reliable partner for international cooperation.
Sixth: The strategy must be implemented effectively. Everything outlined so far is achievable if politics, business, society, and science are behind it. We must agree that we want to use the AI turning point to significantly improve our position in the global IT landscape – and not make the same mistakes as before and settle for niche technologies like domain-specific model fine-tuning or the status of AI users and custodians of data treasures. Location issues for data centers and their infrastructure must be resolved objectively and quickly, without getting bogged down in endless planning and appeals procedures or prioritizing irrelevant criteria.
The energy issue is particularly important: AI is energy-hungry, and its training also requires a high level of supply security. Wind and solar power alone are not sufficient for this; they are subject to strong weather-dependent fluctuations. Switzerland and Norway are therefore planning large AI data centers near hydroelectric power plants, while the United States is planning to locate them near conventional and nuclear power plants. Around the world, AI is driving planning for new power plants, including new nuclear reactors. Energy costs and security of supply should also be decisive factors in the choice of location in our country.
AI data centers with lower security of supply requirements, i.e., those for inference or smaller models, should be built where electricity is generated cheaply, for example, near wind turbines and solar power plants in the north and east, and where it is particularly easy to communicate with the target customers using broadband and low-latency, such as in the greater Frankfurt-Rhine-Main area, which is particularly well connected to the internet via DE-CIX, the world's largest internet exchange.
Data centers with high security of supply requirements should be located near corresponding power plants (i.e., coal, gas, or water), as the otherwise necessary energy transmission capacities are lacking, particularly in a north-south direction. This makes North Rhine-Westphalia a particularly suitable location.
The German government aims to build at least one AI Gigafactory in Germany with EU funding. From a technical perspective, the Jülich Research Center is considered a particularly well-suited location: JUPITER already has an AI-capable high-performance computing system, extensive experience in building and operating such systems, and access to reliable energy and communications.
Unfortunately, the reality in Germany is far removed from such rational considerations. Instead of everyone rallying behind Jülich and planning the next steps in the competition for EU funding for the construction of an AI Gigafactory in Germany, parts of the political and business communities are misunderstanding the choice of location as an instrument of regional development, thus needlessly sacrificing our success in AI.
Decisions like these must be made objectively and scientifically guided, centralized in one place with clear responsibilities and clear authorities.
Speed is particularly critical here – important fundamental questions such as the choice of location for AI data centers must be decided early and quickly; development cycles for models and software stacks currently range between twelve and 18 months.
Nothing slows down large projects more effectively than the diffusion of responsibility combined with complex coordination processes, whether in large industrial consortia or between the bureaucracies of various federal ministries and state governments.
The AI strategy and its implementation should therefore also be made a top priority in Germany, i.e., located in the Federal Chancellery. An appropriately staffed, science-led AI Council should be established from the outset to ensure technical guidance and balance the interests of science, business, and politics. In addition to the federal and state governments, the most important disciplines should be represented, especially from computer science (machine learning, high-performance computing, software, communications, cybersecurity), as well as the most important AI application areas and industries.
Neither the United States' heavily private-sector AI strategy nor China's state-centric approach fit Germany's framework and objectives.
A purely profit-driven corporate approach carries the risk that short-term return goals will neglect basic research, create excessive dependence on individual corporations, and develop strategic technologies without democratic oversight.
A model exclusively controlled by the state, in turn, often suffers from bureaucratic inertia, lengthy decision-making processes, and a lack of market proximity.
A hybrid approach is therefore appropriate for Germany, in which research ensures strategic direction and scientific quality, while industrial partners take over practical implementation and scaling, embedded in clear political guidelines.
The implementation of the strategy should therefore be entrusted to a dedicated, independent German AI agency with the AI Council as its supervisory board. This AI agency should have considerable freedom regarding planning procedures, procurement, and salary structures, as well as a budget secured for several years. To engage all stakeholders, the AI agency should develop a detailed implementation plan that creates the necessary incentives for cooperation and joint funding.
Haya Schulmann is a professor of cybersecurity at the Institute of Computer Science at Goethe University Frankfurt and a member of the board of directors of the National Research Center for Applied Cybersecurity ATHENE.
Michael Waidner is a professor of information technology security in the Department of Computer Science at the Technical University of Darmstadt, director of the Fraunhofer Institute for Secure Information Technology SIT, and chairman of the board of ATHENE.” [1]
1. Deutschland am KI-Wendepunkt. Frankfurter Allgemeine Zeitung; Frankfurt. 01 Sep 2025: 18. Von Haya Schulmann und Michael Waidner
Komentarų nėra:
Rašyti komentarą