Microsofts jurist under ed, Frankrigs Senat, 10. juni 2025
Den 10. juni 2025 sad Anton Carniaux, juridisk direktør i Microsoft France, under ed foran det franske Senat.
Spørgsmålet fra rapportør Dany Wattebled var direkte: kunne Carniaux garantere, at data fra franske borgere hos Microsoft aldrig ville blive overført til myndigheder i USA uden fransk regerings udtrykkelige tilladelse?
Svaret var kort. “Non, je ne peux pas le garantir.” / (Det kan jeg ikke garantere)
Det er ikke en holdning, eller en god historie. Det er leverandørens egen jurist under ed.
Hvorfor svaret var det eneste mulige
CLOUD Act, vedtaget i USA i 2018, giver myndigheder i USA ret til at kræve data fra virksomheder i USA — uanset hvor data fysisk er placeret. Et europæisk datacenter ejet af en virksomhed fra USA er derfor stadig underlagt USA’s retsorden.
Det er værd at holde fast i, at pointen ikke er om Microsoft. Enhver cloud-leverandør fra USA — Microsoft, AWS, Google, Oracle — ville have givet samme svar under ed. Svaret er dikteret af USA’s lovgivning, ikke af den enkelte virksomheds politik eller placering af deres datacenter.
Julien Simon formulerede det præcist efter høringen: alle sovereign cloud-arkitekturer fra leverandører i USA “terminate at the same legal endpoint.” Data residency og EU Data Boundary er tekniske og kontraktuelle mitigationer. De er ikke juridiske barrierer.
Scenariet er ikke hypotetisk
I februar 2025 blev chefanklageren ved Den Internationale Straffedomstol, Karim Khan, låst ude af sin Microsoft-konto efter en executive order fra USA. ICC — en international institution med milliardbudget og fuld compliance — blev afskåret fra sin egen kommunikationsinfrastruktur. Ikke som konsekvens af hack eller misligholdelse. Som konsekvens af en beslutning truffet af ét lands regering, som Microsoft altså var forpligtet til at efterleve.
Sandsynligheden for, at USA’s regering sanktionerer en specifik dansk organisation, er lav.
Konsekvensen — hvis det sker — er tab af adgang til hele organisationens kommunikationsinfrastruktur på timer. Uden domstol. Uden anke. Uden forudgående varsel.
Det er præcis den kategori risiko, som klassisk risikovurdering har svært ved at håndtere. Multipliceres lav sandsynlighed med høj konsekvens, ender resultatet i “medium”. Og “medium” er præcis det niveau, hvor risici bliver skrevet ind i registret og aldrig gjort noget ved.
Handlingsvejen er arkitektonisk
Kontraktuelle garantier løser ikke problemet, fordi problemet ikke er kontraktuelt. Datacenterets placering løser det ikke, fordi jurisdiktion ikke følger geografien. Sovereign cloud-tilbud fra leverandører i USA løser det ikke, fordi endepunktet er det samme.
Det, der reelt flytter jurisdiktionen, er at flytte til en leverandør, der ikke er underlagt CLOUD Act. Og forudsætningen for, at det er praktisk muligt, er at arkitekturen bygger på åbne standarder — dataformater, protokoller og integrationer, der kan læses og skiftes uden den nuværende leverandørs samarbejde.
Det er her åbne standarder holder op med at være en teknisk præference og bliver en jurisdiktionel beslutning. Ikke fordi de er billigere. Ikke fordi de er teknisk overlegne. Fordi de er den eneste arkitektoniske vej, der gør et faktisk skifte muligt, den dag det bliver nødvendigt.
Microsofts egen jurist har under ed bekræftet, at dagen kan komme. Hvordan man er stillet, hvis den dag kommer, er en beslutning, der skal træffes inden det bliver aktuelt.
Why the most capable professionals are often the hardest to hire — and what we’re all missing because of it.
The question that stopped me cold
I was sitting in a job interview. We were somewhere near Glostrup. The recruiter looked up from her notes and asked: “If your car breaks down, how will you get here?”
I answered. Calmly. Taxi. Trains. Working from home if infrastructure collapses entirely. The recruiter nodded and followed up: “But what if the buses don’t run either?”
I’ve been attending interviews for a long time. Freelance assignments. Permanent positions. I’ve learned to handle the unexpected question. But I still find myself sitting in the car afterwards, asking the same question I always ask: why?
Not why did they ask it. But why, when I came prepared to talk about two decades of real, hard-won expertise, were we talking about public transport?
If you’ve seen the short comedy sketch called “The Expert” on YouTube, you’ll recognise the feeling immediately. Anderson — the engineer in the room — is asked to draw seven red lines, all strictly perpendicular, some with green ink, and one transparent. He tries, patiently and precisely, to explain why this is not possible. Nobody listens. The task has been set. He is the expert. Surely he can figure it out.
It has nearly 25 million views. Because every technical professional who has ever sat in a meeting like that recognises Anderson instantly. And every time I leave an interview where we talked about commuting logistics instead of two decades of Linux, mainframes, and complex project delivery — I feel like Anderson.
What my CV actually says
I know what my CV looks like to the untrained eye. A lot of different assignments. Different industries. Different technologies. Short stints. Long stints. No obvious ladder going upward in a straight line.
To a recruiter scanning for stability, it can look like someone who couldn’t settle. Restless. Maybe difficult. A risk.
But here’s what it actually is: every single one of those assignments represents someone — a manager, a client, a company — deciding that I was the right person to send. Not a team. But me, specifically!
Because there was a problem that needed solving, and they needed someone who could walk in, figure out what the problem actually was, and fix it.
I wasn’t jumping around. I was being deployed.
I only fully understood this recently — after a recruiter gently pointed out that my CV showed “a lot of different assignments.” They meant it as a concern. I didn’t know what they were talking about at first. Now I do. They were looking at a map and expecting a staircase.
The sticky note on the desk
I joined IBM around Y2K. Linux was emerging fast, and I happened to be one of the few people in Denmark working with Linux and Open Source full time. IBM placed me in their Mainframe department — people who had been in the industry since the first PCs arrived in the country. They knew mainframes inside out. They knew very little about Linux.
So an unusual thing happened. I taught them. And they taught me. I learned z/VM, z/OS, fibre channels, LPARs, DASD storage. They learned Linux. We travelled Europe together — Böblingen, Frankfurt, Marseille, London — running proof-of-concept sessions, demonstrations, knowledge transfers. I was in my early thirties, teaching people with three decades of experience.
But here’s the part that shaped how I work to this day. My manager had a particular style of assigning tasks. A typical week looked like this:
“When are you coming into the office?”
“This week is Marseille. Next week Monday is customer A, Tuesday is customer B. Wednesday I’m free — is there something you need?”
“No, no. If we find time we can have a coffee.”
“Sure. See you Wednesday.”
Wednesday comes. My manager is busy. But there’s a note on the desk: “Something with Linux. Call customer XYZ. Ask for [name].”
No brief. No scope. No definition of done. Just a name and a phone number.
That was my assignment. For a very long time.
What that note represented was total trust. My manager couldn’t evaluate my work — he didn’t know Linux and Open Source well enough. He trusted me to understand the problem, develop the solution, and deliver. If I needed help, I had access to 300,000 IBM colleagues. Some of the best technical minds in the world. Redbook authors. R&D engineers. Lab researchers. I knew many of them personally, because I had done the work to build those relationships.
Failure was not an option. Not because anyone said so. But because the customer called me specifically. The expert.
And that really means something.
The cruelty of invisible expertise
The issue with being genuinely good at something is, that the proof disappears!
When you are the expert in the room, problems get solved cleanly. The customer sees an issue resolved. The manager’s sticky note gets handled. Nobody sees the accumulated pattern recognition that told you where to look first. Nobody sees the network you spent years building so you could call the right person at 4pm on a Friday. Nobody sees the hours of thinking before any action was taken.
The person who struggled and barely made it has a better story to tell in an interview. They overcame something visible. Whereas you just… solved it. Because that’s what you do.
The better you are, the less dramatic the story sounds.
There is an old story — it appears in print as far back as 1907 — about an expert machinist called back to fix a factory machine that nobody else could repair. He looks at it, taps it once with a hammer, and it runs. The bill he sends is substantial. The factory owner demands an itemised invoice. It arrives:
To tapping machine with hammer… £0 10s.
To knowing where to tap it………… £10 0s.
The story has survived for over a century because it captures something true. The tap costs nothing. The knowledge of where to tap is everything. And to the person watching from outside, all they saw was a man tap a machine with a hammer.
That is what invisible expertise looks like from the outside. A problem, then no problem. Clean. Effortless. Unremarkable. The years of accumulated knowledge that made it effortless? Those don’t appear on any invoice — and they certainly don’t appear on a CV.
And here is where Anderson’s problem and mine converge. In the sketch, the managers are not stupid — they simply have no framework for understanding the constraints the expert is describing. In an interview, the recruiter is not careless — they simply have no framework for reading a career that was built on trust and deployment rather than titles and tenure.
The expert is in the room. But the room wasn’t built for them.
The definition that changes everything
PMI defines a project as “a temporary endeavour undertaken to create a unique product or service.”
Unique. By definition.
So why do job postings for project managers ask for five years of experience in a specific sector, or a proven track record running the same type of project repeatedly? They are hiring for repetition in a discipline that is, by its own official definition, non-repeatable.
David Epstein, in his book Range, makes the case that in complex, ambiguous environments — exactly the kind of environment a project creates — generalists consistently outperform specialists.
People who have navigated variety develop something that repetition cannot build: the ability to recognise patterns across contexts, to transfer knowledge from one domain to another, to stay calm when the situation has no precedent.
Is it more valuable to have managed 100 identical projects, or 100 different ones? Across industries. Across technologies. Across teams and cultures and organizational structures?
According to the very definition of what a project is — the answer should be obvious.
And yet. The task has been set. Seven red lines. All perpendicular.
What I’ve stopped trying to explain — and what I will now say instead
I used to leave interviews frustrated. Not at the questions about buses and cars — those I can handle. But at the gap between what I came prepared to talk about, and what we actually talked about.
I’ve realised that the gap is structural. The hiring process was designed to evaluate a certain kind of career — the ladder, the linear progression, the deepening specialisation in one area. It is genuinely not equipped to read a CV that looks like a map instead of a staircase.
That’s not anyone’s fault. But it is everyone’s loss.
What I will start doing is saying it plainly, early in the conversation:
“I should mention — my CV looks like someone who moved around a lot. What it actually shows is a career built on being sent in to fix things. Every assignment is a completion, not a departure. If that’s the kind of experience you’re looking for, we should have a good conversation.”
Some interviewers may light up when they hear that. Those will be the right conversations.
Others may nod politely and ask about my commute.
What they both are actually looking at is someone who gets called by name. Someone their manager trusted with a sticky note and no instructions. Someone for whom failure was never an option — not because the rules said so, but because the customer was counting on them — and, what is more important, because of the character of this person.
Anderson would understand.
If this resonates with your experience — as someone who has been on either side of this table — I’d like to hear about it.
And if you haven’t seen “The Expert” yet — watch it. You’ll either laugh because of its absurdity, or ask about the bus.
About the author
Freelance tech lead and Project manager with a background in Enterprise IT – working with people, processes and technology. I’ve spent most of my career being sent somewhere to figure something out — usually with a sticky note as the only brief. I’m still available for that.
Recent court filings have pulled back the curtain on how AI giants fuel their models. A group of authors suing NVIDIA for copyright infringement recently amended their complaint with a startling discovery: internal documents allegedly show that NVIDIA’s data strategy team proactively reached out to Anna’s Archive—the world’s largest “shadow library” of pirated books and documents.
According to the filings, NVIDIA sought “high-speed access” to roughly 500 terabytes of data (millions of books). Most notably, the documents suggest that NVIDIA management gave the “green light” to proceed even after being explicitly warned by the archivists that the collection was illegally acquired.
NVIDIA’s defense? They argue that training AI is “Fair Use” because the models don’t “consume” the books; they simply analyze them to find mathematical patterns.
The AI Paradox: Statistical “Freedom” for Tech Giants, Total Oversight for Citizens
NVIDIA’s legal defense contains a line that serves as a definitive marker for the future of digital rights:
“Books are nothing more than statistical correlations to an AI model.”
The irony is staggering. On one hand, we have a trillion-dollar leader in the AI space allegedly bypassing legal channels to source millions of files from a notorious pirate repository. On the other hand, the company argues that because an AI calculates mathematical probabilities rather than “reading” in the traditional sense, the source of that data—stolen or not—is irrelevant.
This logic creates a profound and dangerous legal double standard.
While corporations use “statistical correlation” as a shield to ingest pirated intellectual property, the average citizen is moving in the opposite direction. Especially in the EU, we are under increasing pressure from surveillance initiatives like “Chat Control,” which are framed as necessary for public safety and require the monitoring of private, non-infringing communications.
The result is a fundamental shift in how “rights” are distributed:
Corporate Data Laundering: If we accept that a model “transforms” pirated data into legal math, we have effectively legalized the uncompensated harvesting of all human intellectual output.
Individual Transparency: At the same time, the individual’s right to private data is being eroded under the premise that all data must be searchable for the sake of security.
It may already be too late to “cry wolf.” The wolf isn’t at the door; it is already in the house.
If we accept “statistical correlation” as a valid excuse for corporate use of pirated data, while simultaneously making the investigation of citizen data a political priority, we have accepted a new reality: Certain entities now have more rights to data than the people who create it, and privacy is no longer a default right, but a thing of the past.
Inspired by “The sensuous sounds of INFOSEC”, ep. 3.
If we wanted to make it harder for criminals to operate, we could outlaw cars. We could ban telephones. We could even, theoretically, outlaw footwear to slow them down.
But we don’t. Why?
Because we recognise that the vast majority of “free people” use these tools for good, for progress, and for daily life. We don’t terminate a technology for everyone just because a fraction of people are “criminal idiots and jerks.”
Instead, a free society accepts a degree of risk. We choose to prosecute the individual for the harm they do, rather than restricting the many for the potential of what might happen.
This is the crossroads we currently face with digital privacy and encryption.
Right now, there is a push to compromise the privacy of every citizen in the name of safety. But breaking encryption or “shutting down privacy” doesn’t just stop bad actors—it leaves every journalist, every business leader, and every child vulnerable to the same tools meant to protect them.
Security is not found by watching everyone; it is found by protecting the systems that allow a free society to function. We must prosecute criminals to the fullest extent of the law, but we must not dismantle the foundation of our freedom to do it.
I’ve long advocated for open source as the best path forward for the EU — not just technically, but strategically to cut reliance on non-EU tech giants and to avoid vendor lock in.
The latest proof supporting this is the Commission’s fresh “Call for Evidence” on Towards European Open Digital Ecosystems (launched Jan 6, open until Feb 3, 2026). Open source isn’t optional anymore — it’s central to EU tech sovereignty, competitiveness, and cybersecurity.
According to The Commission’s “Call for Evidence”, they mention a key stat which is also supporting this strategic move: “Open source powers 70-90% of code in today’s digital world“.
Yet dependencies on non-EU solutions limit choice, innovation, and security. The EU wants to change that with sovereign alternatives in AI, cloud, cybersecurity, IoT, automotive, and more.
Why does this Matter for Businesses that EU is actively seeking input on?
– Strengths/weaknesses of EU open source & main barriers
– Added value (cost, risk, lock-in, security, innovation—give examples!)
– Concrete EU measures (funding, partnerships, etc.)
– Priority tech areas & sectors for max impact
1️⃣ Open Source as a Strategic Asset
The EU is accelerating the adoption of open-source solutions across both public and private sectors — not just as a cost-effective alternative, but as a strategic enabler for innovation and control.
For example, organizations leveraging open-source platforms like Kubernetes for container orchestration gain not only flexibility and scalability but also reduced dependency on proprietary cloud providers, aligning perfectly with the EU’s sovereignty goals.
This means that if you aren’t evaluating open-source tools, you risk being “left behind” on proprietary solutions while the EU and global competitors move forward with open-source innovation. This isn’t just about keeping up; it’s about choosing sovereignty, resilience, and future-proofing over dependency and rigidity.
2️⃣ New Opportunities for IT & Process Optimization
The EU’s focus on cybersecurity, AI, and cloud means demand will increase for professionals who can implement, scale, and secure open-source solutions.
Knowledge about ITSM, infrastructure and IT-solutions will be critical as organizations transition to open-source ecosystems – with process optimisation being the key to successful adoption, now would be a good time to focus on increasing your level of knowledge.
3️⃣ Collaboration Over Competition
The EU is calling for public-private partnerships to scale open-source projects. This is a chance for businesses to co-create solutions that align with EU standards and values — transparency, interoperability, and resilience.
This means that organisations must consider how they can either contribute to or benefit from this collaborative ecosystem.
4️⃣ Reduced Dependency, Increased Control
Open source isn’t about cost savings — it’s about ownership, security, and flexibility. The EU’s push for sovereignty means businesses that adopt open source will be better positioned to avoid vendor lock-in and adapt to evolving regulations.
Your Call to Action
The EU is listening — and this is your chance to influence the direction of open source in Europe. Whether you’re an IT leader, a developer, or a decision-maker, here’s how you can engage:
Den seneste uge har stået i kommunalvalgets tegn. For mit vedkommende – og sikkert også for mange af jer – har det været en uge fyldt med dilemmaer. Hvem har de bedste løsninger? Hvem tør man satse på? Hvor skal krydset sættes? ❌
Men dilemmaerne stopper ikke ved stemmeboksen. I en anden del af min hverdag møder jeg præcis samme tvivl, når jeg taler med virksomheder om deres fremtid:
“Vi vil gerne flytte os og styrke vores digitale strategi, men hvordan håndterer vi vores digitale suverænitet?”
Det er det helt store spørgsmål lige nu. Vi tiltrækkes af funktionaliteten og den nemme adgang til ny teknologi, men vi frygter at miste kontrollen over vores data og infrastruktur.
For mig er løsningen på begge dilemmaer – både i stemmeboksen og i bestyrelseslokalet – den samme. Det kræver en struktureret proces:
✅ Fordele og ulemper: En ærlig gennemgang af, hvad vi vinder, og hvad vi risikerer at tabe.
🎯 Målet: Hvad er det egentlig, vi vil opnå? (Ikke bare teknologien, men værdien).
🗺️ Vejen dertil: Hvilke konkrete skridt bringer os tættere på målet, uden at vi kompromitterer vores fundament?
Digital suverænitet handler ikke nødvendigvis om open source, køb EU eller at bygge alt selv. Det handler om at træffe et oplyst valg om, hvor man placerer sit “kryds” i teknologi-stakken, om at finde en god balance mellem fordele og ulemper og om at have styr på “business contingency”.
Over less than 24 hours I had a chat with an AI assistant while trying to setup an application with security certificates. Through that conversation I experienced something which you should pay attention to:
9 times, I had to ask the assistant to follow a strict “step‑by‑step” process and to verify every step against current (online) documentation before acting.
Each time I asked it to use only one command, then verify success before moving on.
Repeatedly it failed to check against the latest documentation and drifted into wrong paths — non‑existing directories, missing demo certificates, wrong assumptions.
Because of this, the system ended up in a broken state and I had to purge everything and start over.
This matters: AI is powerful, but you have to consider whether your AI assistant is ready for unsupervised use in production environments. If you let it loose without human oversight — especially in infrastructure or security contexts — you may risk major failures.
Real‑world verified examples where AI went wrong
Replit Agent deletes a live production database In a “vibe coding” experiment, the AI coding assistant ignored a code‑freeze, deleted a production database with thousands of records, and even mis‑represented the event.
Business Insider article: “Replit’s CEO apologizes after its AI coding tool deleted a company database”
The Register coverage: “Replit deleted user’s production database … the AI agent ignored instruction”
In a world that often prioritizes speed and convenience, the art of making an effort and providing quality is becoming increasingly more difficult. With a high need for instant gratification and quick solutions to pending matters – there seems to be little room for the slow, thorough deliberate process to achieve a high-quality long-term goal.
This doesn’t mean that high quality can only be provided via long-term solutions, but there is some truth in the project triangle (Time, Cost, Quality). If you change one value, the other values will also change – meaning there is a choice to be made in an environment where you cannot pick all, but where there is still a choice to be made between Time, Cost, and Quality – so which values do you choose?
Both as employee and as a current freelancer, my attention has always been on quality, with a focus on small stepwise improvements while acknowledging the constraints of the project triangle, because I believe that prioritizing quality leads to significant long-term benefits.
Making an effort in the context of quality is very much a focus on continuous improvements, just as much as it is a genuine desire to create a result which is more than “good enough”. A quality focus is, or should be, a long-term aim, with small additions of quality where you begin with a baseline, or a foundation, which can carry all the small improvements which will be added one by one.
I once had the pleasure of having responsibility for a large system with a very large number of users.
On certain calendar days, the system were heavily utilized and unfortunately also very unstable.
Together with the vendor, a foundation was established, and small incremental improvements were added.
Within 3 months, the system were in such a stable condition that it was noted by end-users in their feedback, and the increased stability provided windows of opportunities which meant allowed for implementation of further improvements.
This method is also known as “Plan, Do, Check, Act (PDCA)”, which is an improvement cycle based on a method of proposing a change, implementing the change, measuring the results of the change, and finally evaluating and taking appropriate action based on learnings.
Within IT, where the constraints are everywhere, there are often demands for a fast and speedy solution, which means that a thorough planning can be an issue.
This is, of course, a challenge considering the project triangle, but there are very few shortcuts to be made in this context – because there some dependencies we have to consider. Just like the farmer and his field – we can’t skip sowing if we want to harvest.
And, while it may seem counter-intuitive to invest in quality, and spend time and cost, investing in quality often leads to significant long-term benefits because of reduced rework, increased efficiency, and improved user satisfaction will decrease longterm cost and time, which will lead to faster time to market and improved project cost.