Cloud Security Alliance
EMEA Conference
Sovereign Cloud and Artificial Intelligence - two days of training, insights, and actionable strategies for navigating sovereignty regulatory requirements across the globe.
Sovereign Cloud &
Artificial Intelligence
Regulations defining Sovereignty requirements regarding the use of Cloud and AI technologies by data controllers, data processors and their entire supply chain are emerging in many legislations globally. These regulations impose strict requirements regarding legal, contractual, service design and architecture, operational, and compliance-related aspects.
The European Commission has published the Cloud Sovereignty Framework (CSF) which lists 8 core sovereignty domains:
- Strategic sovereignty
- Legal and jurisdictional sovereignty
- Data and AI sovereignty
- Operational sovereignty
- Supply chain sovereignty
- Technology sovereignty
- Security and compliance sovereignty
- Environmental sovereignty
The Event will provide training, background information and actionable insights into sovereignty regulatory requirements across the globe and how to address them from a legal, contractual, design & architecture, risk & compliance point of view, rounded up with practical examples of real world implementation cases.
Event Details
Venue
Amazon Conference Centre
Mythenquai 10
Zurich, Switzerland
Dates
30 September - 01 October 2026
Who Should Attend
CISOs, DPOs, and senior professionals in cyber risk, data protection, supply chain security, compliance, and cloud/AI governance.
Day 1 — Training & Workshop
Wednesday, 30 September 2026
09:00 – 09:30
Registration & Welcome Coffee
09:30 – 12:30
Morning Session
12:30 – 13:30
Lunch Break
13:30 – 17:30
Afternoon Session
17:30
End of Training Session
Day 2 — Conference
Thursday, 1 October 2026
08:30 – 09:00
Registration & Welcome Coffee
09:00 – 09:10
Welcome and Event Introduction by the Conference Hosts
Rolf A. Becker, Lars Ruddigkeit: Co-Presidents CSA Swiss Chapter
Jim Reavis: CEO Cloud Security Alliance
Linda Strick: MD Cloud Security Alliance EMEA
09:10 – 09:40
Agentic AI and Sovereign Cloud: Global and Regional Principles and Concerns — Fire Side Chat
As autonomous AI agents move into production, they collide with a countervailing force: the drive for sovereign control over data, access, and jurisdiction. Agentic systems cross boundaries by design; sovereignty draws them. This session will contrast regulatory requirements emerging, political concerns and opinion, research of the CSA, and implementation concerns. Emerging global principles for sovereignty and trustworthy agentic AI are contrasted with the regional realities shaping Europe, Switzerland, Middle East and Asian emerging regulations — examining accountability, identity, data residency, and cross-border control, and where these principles are still being tested against the hard trade-offs sovereignty demands.
Jim Reavis: CEO Cloud Security Alliance
Lukas Mäder: Editor Technology and Geopolitics, Neue Zürcher Zeitung
09:40 – 10:10
Sovereign Cloud: Global Overview of Regulations and Requirements
Abstract in preparation
Jean-François Terminaux: CSA Sovereign Cloud Working Group
2nd speaker: To be confirmed
10:10 – 11:00
Sovereign Cloud: Regulatory Perspectives Europe, Middle East, Asia and USA — Expert Panel
Abstract in preparation
Bharat Raigangar: Global Head – AI Cyber Security & Risk / 1CxOCSA
Sana Yaakoubi: Digital Risk and AI Governance Leader
Further Speakers: to be confirmed
11:00 – 11:30
Coffee Break & Networking
11:30 – 12:00
CSA AI Foundation, CSA AICM, Audits and more
Cybersecurity has entered the intelligence era, with adversaries operating at machine speed and human-paced governance falling behind. The strategic question is no longer whether to adopt AI, but how to defend and govern when AI is on both sides. This session presents CSA's practical guidance for that shift — how to reorganize security operations for machine speed, where human judgment still matters, and why AI belongs under AI-native frameworks like the AI Controls Matrix rather than retrofitted legacy frameworks.
Jim Reavis: CEO Cloud Security Alliance
Daniele Catteddu: CTO Cloud Security Alliance
12:00 – 12:30
Sovereign Agents: Setting Guardrails by Default
Abstract in preparation
Sudhir Ethiraj: Global Head of Cybersecurity Office (CSO) & CEO Business Unit Cybersecurity Services / TÜV SÜD
12:30 – 13:30
Lunch Break & Networking
13:30 – 14:00
Agentic AI: Translating Principles into Practical Discipline
This session applies two governance frameworks, the fifty-year-old economic theory of the principal–agent theory and Anthropic's newly published "Rule of Two" to a real ten-agent AI system built for professional advisory work, auditing it agent by agent rather than staying at the level of abstract principles. Attendees will see a concrete, repeatable method for finding where risk actually concentrates in a multi-agent architecture: not evenly across every agent, but at aggregation points and unverified third-party data flowing silently through handoffs. The case study is unusual in that the audit isn't a list of failures, it surfaces what the system already got right by design, and uses that to explain why it worked, so the pattern can be deliberately repeated elsewhere. Audience takeaway: a three-question checklist they can run against their own agent systems by the end of the talk, not just a framework to remember.
Monika Atanasova: Founder / Tedarion
14:00 – 14:30
Achieving Digital Sovereignty in Practice: Case Study
Digital sovereignty is of strategic importance for many jurisdictions globally, including the EU member states, Switzerland, UAE, Saudi Arabia, China, Singapore, USA and many more. The gradual and increasingly intensive use of international digital ecosystems in recent years has been primarily with a view to cost advantages; at the same time, a strategic dependency was created, which is now the focus. The presentation uses a practical case study to show how partial or overall sovereignty can be achieved step by step. Both organizational and technical aspects are addressed. At the same time, a strategy is presented that leads to successful implementation in iterative form.
Rolf von Rössing: Prof. h.c. Universität für Weiterbildung Krems, Partner at FORFA Consulting, ISACA Board of Directors
14:30 – 15:00
Implementation of Sovereign Cloud: Legal Framework for the Supply Chain, Leveraging Zero Trust and Reigning in on AI — Expert Panel
Abstract in preparation
Rolf A. Becker: Co-President CSA Swiss Chapter
Tereza Jášková: Managing Director & Senior Legal Counsel / Alpiq
Sana Yaakoubi: Digital Risk and AI Governance Leader
15:00 – 15:30
Contractual Aspects of Sovereign Cloud and AI
Abstract in preparation
David Rosenthal: Partner at VISCHER, Delegate of the Board at LawDigital Ltd.
15:30 – 16:00
Coffee Break & Networking
16:00 – 16:30
Implementation of AI under Sovereignty Restrictions: Succeeding in a Regulated Market — Case Study from Singapore
Abstract in preparation
Dr. Sina Wulfmeyer: Chief Data Officer & Board Member / Unique AI
Michael Dreher: CISO / Unique AI
16:30 – 17:00
Implementation of Sovereign Cloud: Company Perspective Middle East
Abstract in preparation
Sara Alnoaimi: Head of Cybersecurity at Drilling & Workover Operations / aramco
17:00 – 17:30
Implementation of Sovereign Cloud: Company Perspective Europe
Abstract in preparation
Katia Winkler: Group Information Security Manager, Deputy CISO / Vaillant Group
17:30 – 17:50
Implementation of Sovereign Cloud: Provider Perspective and Platform Toolkit Best Practice
Abstract in preparation
Lars Ruddigkeit: Co-President CSA Swiss Chapter, Amazon
17:50 – 18:00
Wrap-up by the Conference Hosts
Rolf A. Becker, Lars Ruddigkeit: Co-Presidents CSA Swiss Chapter
Jim Reavis: CEO Cloud Security Alliance
Linda Strick: MD Cloud Security Alliance EMEA
18:00
Networking Apéro
End of the Conference
Who Should Attend
Senior Leadership
CISOs, DPOs, and senior professionals responsible for cyber risk governance and control.
Risk & Compliance
Heads of third party risk management, supply chain compliance, GRC, audit, and operational risk.
Technical Leaders
Heads of cloud, AI and cyber security, security architecture, IT risk, and business continuity.
Distinguished speakers
Katia Winkler
Group Information Security Manager, Deputy CISO at Vaillant Group
Lukas Mäder
Editor Technology and Geopolitics at Neue Zürcher Zeitung
The Event Organiser
The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organisation committed to awareness, implementation, and credentialing of AI, Cloud, Zero Trust.
Event Partners
SCCS Summit
The SCCS Third Party & Supply Chain Cyber Security Summit brings together senior Information Security & Cyber TPRM leaders to address one of today's most urgent challenges: how to secure the extended enterprise in an era of escalating cyber threats and growing regulatory pressure.
Dr. Peter van Eijk
Dr. Peter van Eijk is one of the world's most experienced cloud trainers: Technology for decision makers. Developing and delivering training and coaching programs for Cloud, AI and Security.
Join us in Zurich
Register now to secure your place at the premier cloud sovereignty event in EMEA.
Register Now